First published: Mon May 12 2025(Updated: )
afpfs. The issue was addressed with improved memory handling.
Credit: Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeCsaba Fitzl @theevilbit Kandjian anonymous researcher Dayton Pidhirney Atredis PartnersLyutoon YenKoc Mateusz Krzywicki @krzywix Michael DePlante @izobashi Trend Micro Zero Day InitiativeLucas Leong @_wmliang_ Trend Micro Zero Day InitiativeChristian Kohlschütter CVE-2024-8176 Paweł Płatek (Trail BitsLFY @secsys Fudan Universitywac Dave G. Kirin @Pwnrin 7feilee Eric Dorphy Twin Cities App Dev LLCAdam M. CVE-2025-26465 CVE-2025-26466 Lyutoon Atredis PartnersYenKoc Atredis PartnersJoseph Ravichandran @0xjprx MIT CSAILDillon Franke Google Project Zerowac Trend Micro Zero Day Initiative
Affected Software | Affected Version | How to fix |
---|---|---|
<13.7.6 | 13.7.6 | |
macOS Ventura | <13.7.6 | 13.7.6 |
Apple macOS | <14.7.6 | 14.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The severity of CVE-2025-24155 is rated as high due to the potential for exploitation leading to significant security risks.
To fix CVE-2025-24155, update to macOS Ventura version 13.7.6 or macOS Sonoma version 14.7.6.
CVE-2025-24155 affects macOS Ventura versions up to 13.7.6 and macOS Sonoma versions up to 14.7.6.
CVE-2025-24155 addresses issues such as memory handling improvements and input sanitization vulnerabilities.
The potential impacts of CVE-2025-24155 include arbitrary code execution and system instability due to double-free vulnerabilities.