CVE-2025-24085

high

Description

A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.

References

https://www.securityweek.com/apple-patches-recent-zero-days-in-older-iphones/

https://www.bleepingcomputer.com/news/security/apple-backports-zero-day-patches-to-older-iphones-and-macs/

https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html

https://www.darkreading.com/mobile-security/apple-drops-another-webkit-zero-day-bug

https://www.bleepingcomputer.com/news/apple/apple-fixes-webkit-zero-day-exploited-in-extremely-sophisticated-attacks/

https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html

https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-day-exploited-in-extremely-sophisticated-attacks/

https://thehackernews.com/2025/02/apple-patches-actively-exploited-ios.html

https://securityaffairs.com/174066/hacking/apple-fixes-iphone-and-ipad-bug-exploited-in-extremely-sophisticated-attacks.html

https://www.cisa.gov/news-events/alerts/2025/01/29/cisa-adds-one-known-exploited-vulnerability-catalog

https://www.securityweek.com/apple-patches-first-exploited-ios-zero-day-of-2025/

https://thehackernews.com/2025/01/apple-patches-actively-exploited-zero.html

https://www.forbes.com/sites/kateoflahertyuk/2025/01/27/ios-183-update-now-warning-issued-to-all-iphone-users/

https://www.darkreading.com/endpoint-security/apple-patches-actively-exploited-zero-day-vulnerability

https://www.bleepingcomputer.com/news/security/apple-fixes-this-years-first-actively-exploited-zero-day-bug/

https://support.apple.com/en-us/122073

https://support.apple.com/en-us/122072

https://support.apple.com/en-us/122071

https://support.apple.com/en-us/122068

https://support.apple.com/en-us/122066

Details

Source: Mitre, NVD

Published: 2025-01-27

Updated: 2025-03-21

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High