#VU103332 Buffer overflow in Apple iOS and iPadOS - CVE-2025-24126

 

#VU103332 Buffer overflow in Apple iOS and iPadOS - CVE-2025-24126

Published: January 27, 2025


Vulnerability identifier: #VU103332
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-24126
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
Apple iOS
iPadOS
Software vendor:
Apple Inc.

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in AirPlay. A remote attacker on the local network can send specially crafted input to the device, trigger memory corruption and execute arbitrary code on the target system.



Remediation

Install updates from vendor's website.

External links