Buffer overflow in iPadOS - CVE-2025-24111
Published: May 13, 2025
Vulnerability identifier: #VU108994
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-24111
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error in Display. A local application can trigger memory corruption and escalate privileges on the system.
Affected software
iPadOS
visionOS
watchOS
macOS
tvOS
Apple iOS
visionOS
watchOS
macOS
tvOS
Apple iOS
How to mitigate CVE-2025-24111
Install updates from vendor's website.
iPadOS - addressed in versions 17.7.7, 18.3 22D60
visionOS - update to 2.3
watchOS - update to 11.3
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.3 24D60
tvOS - update to 18.3
Apple iOS - update to 18.3 22D60
visionOS - update to 2.3
watchOS - update to 11.3
macOS - addressed in versions 13.7.5 22H527, 14.7.5 23H527, 15.3 24D60
tvOS - update to 18.3
Apple iOS - update to 18.3 22D60
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iPadOS 17
- Multiple vulnerabilities in macOS Sonoma
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in Apple visionOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple watchOS