ZeroHour
CyberScooppublished ()ingested @gregotto

Apple’s latest patch closes zero

criticalVulnerability exploited in the wildimportance 60CVE-2025-24085

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24085
Use-After-Free Privilege Escalation in Apple iOS, iPadOS, macOS and Other Platforms

CVE-2025-24085 is a use-after-free memory corruption flaw (CWE-416) in multiple Apple operating systems that Apple addressed with improved memory management. It is triggered by a malicious application already running on a vulnerable device, which can exploit the flaw to elevate its privileges. An attacker who tricks a user into installing and running a malicious app could gain elevated rights beyond the app's sandbox. All users of unpatched iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets, and Apple Watches are potentially affected, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-29. Apple has confirmed the issue was actively exploited against versions of iOS before iOS 17.2, indicating in-the-wild exploitation, though no public proof-of-concept is known.

Do: Update devices to iOS/iPadOS 18.3 (or iPadOS 17.7.6 on older devices), macOS Sequoia 15.3 / Sonoma 14.7.5 / Ventura 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3 as soon as possible. Because Apple reports active exploitation against iOS versions before 17.2, treat any iPhone or iPad still below iOS 17.2 as at elevated risk and prioritize it for patching. Inventory Apple device fleets via MDM and confirm updated OS builds are deployed, given the CISA KEV listing and the ~18% 30-day EPSS score.

10.018% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 18.3 (actively exploited against iOS versions before iOS 17.2)
  • Apple iPadOS versions prior to iPadOS 18.3 and prior to iPadOS 17.7.6
  • Apple macOS Sequoia versions prior to 15.3
  • +5 more
mass≈1 billion+ devices (Apple's active installed base spans iOS, iPadOS, macOS, watchOS, tvOS, and visionOS)
Full article499 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The zero-day impacts Apple’s framework that manages audio and video playback.

Listen to this article

0:00

Learn more.

(Getty Images)

Apple released software updates Monday, aimed at addressing multiple security vulnerabilities within its products, including a significant zero-day vulnerability. 

Tracked as CVE-2025-24085, the flaw is a use-after-free vulnerability in the company’s Core Media component, a framework that manages audio and video playback and is central to many of Apple’s multimedia applications. The vulnerability poses a serious risk as it has reportedly been exploited in the wild against certain versions of iOS. 

In its advisory, Apple confirmed that malicious applications could exploit this vulnerability to gain unauthorized access to system controls. The company refrained from disclosing specific details about exploitation and potential targets, following its typical practice of limiting information that could aid malicious actors. Despite the swift response from Apple, exploit details remain scant, and the absence of a common vulnerability scoring system (CVSS) severity rating may complicate assessments of the flaw.

The software updates address the vulnerability across a range of devices, including iPhones, iPads, Macs, Apple TVs, the Vision Pro headset, and the Apple Watch. Users of iOS devices from iPhone XS and later, as well as numerous iPad models, are urged to update to iOS 18.3 or iPadOS 18.3. Mac users running macOS Sequoia should upgrade to version 15.3, while Apple Watch users need to install watchOS 11.3 to mitigate risks associated with this vulnerability.

The patchers also resolve five additional security flaws identified in AirPlay, which could enable attackers to cause unexpected system terminations or execute arbitrary code. Notably, the Google Threat Analysis Group played a role in identifying three vulnerabilities in the CoreAudio component. 

You can read more about the updates on Apple’s website.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-security-update-zero-day-january-2025/