First published: Mon Jan 27 2025(Updated: )
Accessibility. An authentication issue was addressed with improved state management.
Credit: product-security@apple.com Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) an anonymous researcher CVE-2025-24085 DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit @RenwaX23 Michael DePlante @izobashi Trend Micro Zero Day InitiativeDesmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeMinghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityGoogle Threat Analysis Group Josh Parnham @joshparnham Uri Katz (Oligo Security) Kirin @Pwnrin Hichem Maloufi Hakim Boukhadra mastersplinter Abhay Kailasia @abhay_kailasia CHossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsArsenii Kostromin (0x3c3e) Adam M. PixiePoint Security Pedro Tôrres @t0rr3sp3dr0 神罚 @Pwnrin Zhongquan Li @Guluisacat Wang Yu CyberservalMatej Moravec @MacejkoMoravec Joshua Jones Joseph Ravichandran @0xjprx MIT CSAIL云散 Mickey Jin @patch1t Bohdan Stasiuk @Bohdan_Stasiuk
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <18.3 | 18.3 |
Apple Mobile Safari | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <11.3 | 11.3 |
visionOS | <2.3 | 2.3 |
visionOS | <2.3 | |
Apple Mobile Safari | <18.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
macOS | <15.3 | |
Apple iOS, iPadOS, and watchOS | <11.3 | |
tvOS | <18.3 | |
macOS | <15.3 | 15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2025-24158 has a high severity rating due to multiple critical issues including authentication, null pointer dereference, type confusion, and input validation problems.
To fix CVE-2025-24158, update your Apple device to the latest version available, which addresses the identified vulnerabilities.
CVE-2025-24158 affects several Apple products including visionOS, Safari, iOS, iPadOS, macOS Sequoia, watchOS, and tvOS.
The vulnerable versions for CVE-2025-24158 include visionOS versions prior to 2.3, Safari versions prior to 18.3, iOS and iPadOS versions prior to 18.3, macOS Sequoia prior to 15.3, and watchOS prior to 11.3.
CVE-2025-24158 includes vulnerabilities related to authentication state management, null pointer dereference, type confusion, and input validation.