First published: Wed Dec 11 2024(Updated: )
Accessibility. An authentication issue was addressed with improved state management.
Credit: product-security@apple.com an anonymous researcher Ben Roeder CVE-2024-45490 Guilherme Rambo Best Buddy Apps风沐云烟 @binary_fmyy Talal Haj Bakry Mysk IncTommy Mysk @mysk_co Mysk IncJacob Braun Michael DePlante @izobashi Trend Micro's Zero Day InitiativeAbhay Kailasia @abhay_kailasia CSeunghyun Lee Gary Kwong sohybbyk Joseph Ravichandran @0xjprx MIT CSAILBenjamin Hornbeck ZUSO ARTSkadz @skadz108 ZUSO ARTChi Yuan Chang ZUSO ARTtaikosoup Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeJunsung Lee Trend Micro Zero Day InitiativeUri Katz (Oligo Security) Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityGoogle Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit Ivan Fratric Google Project ZeroHichem Maloufi Hakim Boukhadra mastersplinter @RenwaX23 Michael DePlante @izobashi Trend Micro Zero Day InitiativeKirin @Pwnrin Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and iPadOS | <18.3 | |
Apple iOS, iPadOS, and macOS | <18.3<17.7.3 | |
Apple iOS, iPadOS, and macOS | <17.7.3 | 17.7.3 |
Apple iOS and iPadOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and macOS | <18.3 | 18.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24091 is considered a moderate severity vulnerability due to the potential for denial-of-service and impersonation of sensitive notifications.
To mitigate CVE-2025-24091, update to iOS 18.3 or iPadOS 18.3, or iPadOS 17.7.3.
CVE-2025-24091 affects Apple devices running iOS versions up to 18.3 and iPadOS versions up to 18.3 and 17.7.3.
An attacker could potentially exploit CVE-2025-24091 to impersonate system notifications or cause a denial-of-service.
No, CVE-2025-24091 is not fixed in versions prior to iOS 18.3 and iPadOS 17.7.3.