Use-after-free in Apple iOS and iPadOS - CVE-2025-24085

 

Use-after-free in Apple iOS and iPadOS - CVE-2025-24085

Published: January 27, 2025 / Updated: May 23, 2025


Vulnerability identifier: #VU103330
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24085
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in CoreMedia. A local application can execute arbitrary code with elevated privileges.

Note, the vulnerability is being actively exploited in the wild.

Affected software

Apple iOS
iPadOS
visionOS
watchOS
macOS
tvOS

How to mitigate CVE-2025-24085

Install updates from vendor's website.

Apple iOS - update to 18.3 22D60
iPadOS - addressed in versions 18.3 22D60, 17.7.6
visionOS - update to 2.3
watchOS - update to 11.3
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.3 24D60
tvOS - update to 18.3

External References

Related Security Bulletins