Input validation error in macOS - CVE-2024-54525
Published: March 18, 2025 / Updated: March 25, 2025
Vulnerability details
The vulnerability allows an attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in MobileBackup when restoring data from a backup file. An attacker can trick the victim into restoring data from a specially crafted backup and modify protected system files.
Affected software
visionOS
watchOS
tvOS
iPadOS
Apple iOS
How to mitigate CVE-2024-54525
visionOS - update to 2.2
watchOS - update to 11.2
tvOS - update to 18.2
iPadOS - update to 18.2 22C152
Apple iOS - update to 18.2 22C152