Use-after-free in Apple iOS and iPadOS - CVE-2025-24085
Published: January 27, 2025 / Updated: May 23, 2025
Vulnerability identifier: #VU103330
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24085
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in CoreMedia. A local application can execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.Affected software
Apple iOS
iPadOS
visionOS
watchOS
macOS
tvOS
iPadOS
visionOS
watchOS
macOS
tvOS
How to mitigate CVE-2025-24085
Install updates from vendor's website.
Apple iOS - update to 18.3 22D60
iPadOS - addressed in versions 18.3 22D60, 17.7.6
visionOS - update to 2.3
watchOS - update to 11.3
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.3 24D60
tvOS - update to 18.3
iPadOS - addressed in versions 18.3 22D60, 17.7.6
visionOS - update to 2.3
watchOS - update to 11.3
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.3 24D60
tvOS - update to 18.3
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in macOS Sonoma
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in iPadOS 17