ZeroHour

CVE-2025-24085

KEVmass

Use-After-Free Privilege Escalation in Apple iOS, iPadOS, macOS and Other Platforms

CISA: Apple Multiple Products Use-After-Free Vulnerability

CVSS 3.1
10.0 critical
EPSS
18%p97
Published
()
KEV added
AI analysis

CVE-2025-24085 is a use-after-free memory corruption flaw (CWE-416) in multiple Apple operating systems that Apple addressed with improved memory management. It is triggered by a malicious application already running on a vulnerable device, which can exploit the flaw to elevate its privileges. An attacker who tricks a user into installing and running a malicious app could gain elevated rights beyond the app's sandbox. All users of unpatched iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets, and Apple Watches are potentially affected, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-29. Apple has confirmed the issue was actively exploited against versions of iOS before iOS 17.2, indicating in-the-wild exploitation, though no public proof-of-concept is known.

What to do: Update devices to iOS/iPadOS 18.3 (or iPadOS 17.7.6 on older devices), macOS Sequoia 15.3 / Sonoma 14.7.5 / Ventura 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3 as soon as possible. Because Apple reports active exploitation against iOS versions before 17.2, treat any iPhone or iPad still below iOS 17.2 as at elevated risk and prioritize it for patching. Inventory Apple device fleets via MDM and confirm updated OS builds are deployed, given the CISA KEV listing and the ~18% 30-day EPSS score.

Affected
Apple iPhone OS (iOS)versions prior to iOS 18.3 (actively exploited against iOS versions before iOS 17.2)
Apple iPadOSversions prior to iPadOS 18.3 and prior to iPadOS 17.7.6
Apple macOS Sequoiaversions prior to 15.3
Apple macOS Sonomaversions prior to 14.7.5
Apple macOS Venturaversions prior to 13.7.5
Apple tvOSversions prior to 18.3
Apple visionOSversions prior to 2.3
Apple watchOSversions prior to 11.3
Estimated exposure
mass≈1 billion+ devices (Apple's active installed base spans iOS, iPadOS, macOS, watchOS, tvOS, and visionOS) — The flaw affects every current Apple operating system simultaneously, and Apple's combined active device base has publicly exceeded a billion units, so exposure is effectively the entire unpatched Apple fleet; the exact share still running…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, visionos, watchos
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news