CVE-2025-24085
Severity CVSS v4.0:
Pending analysis
Type:
CWE-416
Use After Free
Publication date:
27/01/2025
Last modified:
14/11/2025
Description
A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
Impact
Base Score 3.x
10.00
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | 17.7.6 (excluding) | |
| cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | 18.0 (including) | 18.3 (excluding) |
| cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | 18.3 (excluding) | |
| cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | 13.7.5 (excluding) | |
| cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | 14.0 (including) | 14.7.5 (excluding) |
| cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | 15.0 (including) | 15.3 (excluding) |
| cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | 18.3 (excluding) | |
| cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* | 2.3 (excluding) | |
| cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | 11.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://support.apple.com/en-us/122066
- https://support.apple.com/en-us/122068
- https://support.apple.com/en-us/122071
- https://support.apple.com/en-us/122072
- https://support.apple.com/en-us/122073
- http://seclists.org/fulldisclosure/2025/Apr/10
- http://seclists.org/fulldisclosure/2025/Apr/5
- http://seclists.org/fulldisclosure/2025/Apr/9
- http://seclists.org/fulldisclosure/2025/Jan/12
- http://seclists.org/fulldisclosure/2025/Jan/13
- http://seclists.org/fulldisclosure/2025/Jan/15
- http://seclists.org/fulldisclosure/2025/Jan/19
- http://seclists.org/fulldisclosure/2025/Jun/19
- http://seclists.org/fulldisclosure/2025/Oct/1
- http://seclists.org/fulldisclosure/2025/Oct/23
- http://seclists.org/fulldisclosure/2025/Oct/30
- http://seclists.org/fulldisclosure/2025/Oct/31
- https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
- https://github.com/cisagov/vulnrichment/issues/194
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24085



