USN-7929-1: usbmuxd vulnerability
USN-7929-1: usbmuxd vulnerability
Publication date: 15 December 2025
Overview: usbmuxd could be made to overwrite files.
Packages
- usbmuxd - USB multiplexor daemon for iPhone and iPod Touch devices
Details
It was discovered that usbmuxd incorrectly handled certain paths received
with the SavePairRecord command. A local attacker could possibly use this
issue to delete and write files named *.plist in arbitrary locations.
Update instructions
In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions:
- 25.10 questing usbmuxd – 1.1.1-6ubuntu0.25.10.1
- 25.04 plucky usbmuxd – 1.1.1-6ubuntu0.25.04.1
- 24.04 LTS noble usbmuxd – 1.1.1-5~exp3ubuntu2.1
- 22.04 LTS jammy usbmuxd – 1.1.1-2ubuntu0.1

