CVE-2025-24159
CVE-2025-24159
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to execute arbitrary code with kernel privileges.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Apple · iOS and iPadOSApple · iPadOSApple · macOSApple · tvOSApple · visionOSApple · watchOSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://seclists.org/fulldisclosure/2025/Jan/13http://seclists.org/fulldisclosure/2025/Jan/14http://seclists.org/fulldisclosure/2025/Jan/15http://seclists.org/fulldisclosure/2025/Jan/16http://seclists.org/fulldisclosure/2025/Jan/18http://seclists.org/fulldisclosure/2025/Jan/19https://support.apple.com/en-us/122066https://support.apple.com/en-us/122067https://support.apple.com/en-us/122068https://support.apple.com/en-us/122069https://support.apple.com/en-us/122071https://support.apple.com/en-us/122072