Junglewise Threat Intelligence

CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerability

CVE-2025-24085 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-01-29

Technologies: Apple macOS Sonoma, Apple watchOS, Apple macOS Ventura, Apple iPadOS, Apple Tvos, Apple Visionos, Apple Multiple Products. Vendors: Apple.

Executive brief

A use-after-free vulnerability in multiple Apple operating systems allows a malicious application to elevate privileges. The issue was addressed through improved memory management across iOS, macOS, and other platforms.

Affected products

  • Apple iOS before 18.3
  • Apple iPadOS before 18.3, before 17.7.6
  • Apple macOS Sequoia before 15.3
  • Apple macOS Sonoma before 14.7.5
  • Apple macOS Ventura before 13.7.5
  • Apple tvOS before 18.3
  • Apple visionOS before 2.3
  • Apple watchOS before 11.3

Timeline

  • 2025-01-29: disclosed
  • 2025-01-29: patched: Fixed in iOS 18.3, iPadOS 18.3, iPadOS 17.7.6, macOS 15.3, 14.7.5, 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3
  • 2025-01-29: kev added
  • 2025-01-29: exploited: Apple is aware of reports that this issue may have been actively exploited against versions of iOS before iOS 17.2.

Related threats