Apple zero-day vulnerability exploited to target iPhone users (CVE-2025-24085)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24085 | Use-After-Free Privilege Escalation in Apple iOS, iPadOS, macOS and Other Platforms CVE-2025-24085 is a use-after-free memory corruption flaw (CWE-416) in multiple Apple operating systems that Apple addressed with improved memory management. It is triggered by a malicious application already running on a vulnerable device, which can exploit the flaw to elevate its privileges. An attacker who tricks a user into installing and running a malicious app could gain elevated rights beyond the app's sandbox. All users of unpatched iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets, and Apple Watches are potentially affected, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-29. Apple has confirmed the issue was actively exploited against versions of iOS before iOS 17.2, indicating in-the-wild exploitation, though no public proof-of-concept is known. Do: Update devices to iOS/iPadOS 18.3 (or iPadOS 17.7.6 on older devices), macOS Sequoia 15.3 / Sonoma 14.7.5 / Ventura 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3 as soon as possible. Because Apple reports active exploitation against iOS versions before 17.2, treat any iPhone or iPad still below iOS 17.2 as at elevated risk and prioritize it for patching. Inventory Apple device fleets via MDM and confirm updated OS builds are deployed, given the CISA KEV listing and the ~18% 30-day EPSS score. | 10.0 | 18% | KEV |
| mass≈1 billion+ devices (Apple's active installed base spans iOS, iPadOS, macOS, watchOS, tvOS, and visionOS) |
Full article315 words · extracted from helpnetsecurity.com · click to collapse
Apple has shipped a fix for a zero-day vulnerability (CVE-2025-24085) that is being leveraged by attackers against iPhone users.

About CVE-2025-24085
CVE-2025-24085 is a use after free bug in CoreMedia, a framework used by Apple devices for the processing of media data.
The vulnerability can be triggered by a malicious application and may allow attackers to elevate privileges on targeted devices.
“Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2,” the company stated in the notes accompanying the release of iOS and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3, and visionOS 2.3.
Older iOS, iPadOS and macOS branches are likely to receive the fix for CVE-2025-24085 when the next batch of updates is released.
There is no additional information on how the vulnerability is being exploited and by whom. Official credit for its discovery has been witheld.
While it’s likely that the attackers are using this flaw in limited, targeted attacks, all users of Apple devices should update them as soon as possible, as the updates carry fixes for many other vulnerabilities.
Apple Intelligence switched on by default
iOS users should also be aware that iOS 18.3 comes with Apple Intelligence – Apple’s artificial intelligence system that’s built into iOS 18, iPadOS 18, and macOS Sequoia – enabled by default on supported devices.
The exception are devices used in the EU and mainland China, as the service is not available in those regions.
Apple Intelligence can be turned off in iOS, iPadOS and macOS devices’ (System) Settings, under “Apple Intelligence & Siri”.
UPDATE (April 1, 2025, 05:15 a.m. ET):
Apple has backported the patches for CVE-2025-24085 to iOS/iPadOS 17 and macOS 14 and 13.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/28/apple-zero-day-vulnerability-exploited-to-target-iphone-cve-2025-24085/