First published: Mon Jan 27 2025(Updated: )
A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.
Credit: Uri Katz (Oligo Security) Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityGoogle Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit @RenwaX23 Michael DePlante @izobashi Trend Micro Zero Day Initiativean anonymous researcher Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabHichem Maloufi Hakim Boukhadra mastersplinter Kirin @Pwnrin Johan Carlsson (joaxcar) Abhay Kailasia @abhay_kailasia C product-security@apple.com Mickey Jin @patch1t Bohdan Stasiuk @Bohdan_Stasiuk Wang Yu CyberservalMatej Moravec @MacejkoMoravec Arsenii Kostromin (0x3c3e) Joshua Jones Joseph Ravichandran @0xjprx MIT CSAIL云散 Pedro Tôrres @t0rr3sp3dr0 Josh Parnham @joshparnham 神罚 @Pwnrin Zhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsAdam M. PixiePoint Security
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
visionOS | <2.3 | 2.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | |
iStyle @cosme iPhone OS | <18.3 | |
Apple iOS and macOS | <15.3 | |
tvOS | <18.3 | |
visionOS | <2.3 | |
Apple iOS, iPadOS, and watchOS | <11.3 | |
visionOS | <2.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
macOS | <15.3 | |
Apple iOS, iPadOS, and watchOS | <11.3 | |
tvOS | <18.3 | |
macOS | <15.3 | 15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The severity of CVE-2025-24129 is considered critical due to its potential to cause unexpected app termination by a remote attacker.
To fix CVE-2025-24129, update your system to the latest versions: visionOS 2.3, iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, or tvOS 18.3.
CVE-2025-24129 affects Apple visionOS, iOS, iPadOS, macOS Sequoia, watchOS, and tvOS up to specific versions.
CVE-2025-24129 describes a type confusion issue that could be exploited to terminate applications unexpectedly.
CVE-2025-24129 includes an authentication issue that has been addressed with improved checks.