Out-of-bounds write in Apple iOS and iPadOS - CVE-2025-24154
Published: January 27, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error when processing untrusted input in WebContentFilter. A remote attacker can trick the victim into opening a specially crafted file, trigger an out-of-bounds write and perform a denial of service (DoS) attack.
Affected software
iPadOS
visionOS
macOS
How to mitigate CVE-2025-24154
iPadOS - update to 18.3 22D60
visionOS - update to 2.3
macOS - addressed in versions 13.7.3 22H417, 14.7.3 23H417, 15.3 24D60