Apple’s latest patch closes zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24085 | Use-After-Free Privilege Escalation in Apple iOS, iPadOS, macOS and Other Platforms CVE-2025-24085 is a use-after-free memory corruption flaw (CWE-416) in multiple Apple operating systems that Apple addressed with improved memory management. It is triggered by a malicious application already running on a vulnerable device, which can exploit the flaw to elevate its privileges. An attacker who tricks a user into installing and running a malicious app could gain elevated rights beyond the app's sandbox. All users of unpatched iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets, and Apple Watches are potentially affected, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-29. Apple has confirmed the issue was actively exploited against versions of iOS before iOS 17.2, indicating in-the-wild exploitation, though no public proof-of-concept is known. Do: Update devices to iOS/iPadOS 18.3 (or iPadOS 17.7.6 on older devices), macOS Sequoia 15.3 / Sonoma 14.7.5 / Ventura 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3 as soon as possible. Because Apple reports active exploitation against iOS versions before 17.2, treat any iPhone or iPad still below iOS 17.2 as at elevated risk and prioritize it for patching. Inventory Apple device fleets via MDM and confirm updated OS builds are deployed, given the CISA KEV listing and the ~18% 30-day EPSS score. | 10.0 | 18% | KEV |
| mass≈1 billion+ devices (Apple's active installed base spans iOS, iPadOS, macOS, watchOS, tvOS, and visionOS) |
Full article499 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The zero-day impacts Apple’s framework that manages audio and video playback.
Listen to this article
0:00
Learn more.
Apple released software updates Monday, aimed at addressing multiple security vulnerabilities within its products, including a significant zero-day vulnerability.
Tracked as CVE-2025-24085, the flaw is a use-after-free vulnerability in the company’s Core Media component, a framework that manages audio and video playback and is central to many of Apple’s multimedia applications. The vulnerability poses a serious risk as it has reportedly been exploited in the wild against certain versions of iOS.
In its advisory, Apple confirmed that malicious applications could exploit this vulnerability to gain unauthorized access to system controls. The company refrained from disclosing specific details about exploitation and potential targets, following its typical practice of limiting information that could aid malicious actors. Despite the swift response from Apple, exploit details remain scant, and the absence of a common vulnerability scoring system (CVSS) severity rating may complicate assessments of the flaw.
The software updates address the vulnerability across a range of devices, including iPhones, iPads, Macs, Apple TVs, the Vision Pro headset, and the Apple Watch. Users of iOS devices from iPhone XS and later, as well as numerous iPad models, are urged to update to iOS 18.3 or iPadOS 18.3. Mac users running macOS Sequoia should upgrade to version 15.3, while Apple Watch users need to install watchOS 11.3 to mitigate risks associated with this vulnerability.
The patchers also resolve five additional security flaws identified in AirPlay, which could enable attackers to cause unexpected system terminations or execute arbitrary code. Notably, the Google Threat Analysis Group played a role in identifying three vulnerabilities in the CoreAudio component.
You can read more about the updates on Apple’s website.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-security-update-zero-day-january-2025/