First published: Mon Jan 27 2025(Updated: )
AirPlay. A null pointer dereference was addressed with improved input validation.
Credit: Mickey Jin @patch1t Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityWang Yu CyberservalKirin @Pwnrin Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple(HyeongSeok Jang) Trend Micro Zero Day InitiativeArsenii Kostromin (0x3c3e) Joshua Jones DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n an anonymous researcher Ivan Fratric Google Project Zero风(binary_fmyy) Minghao Lin@(Y1nKoc) Pedro Tôrres @t0rr3sp3dr0 神罚 @Pwnrin Anonymous Trend Micro Zero Day InitiativeYiğit Can YILMAZ @yilmazcanyigit Michael DePlante @izobashi Trend Micro Zero Day InitiativeZhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeJunsung Lee Rodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsPixiePoint Security Bohdan Stasiuk @Bohdan_Stasiuk CertiK SkyFall Team Google Threat Analysis Group Joseph Ravichandran @0xjprx MIT CSAILpattern-f @pattern_F_ Jonathan Bar Or @yo_yo_yo_jbo MicrosoftAdam M. Uri Katz (Oligo Security) Pwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 Song Hyun Bae @bshyuunn Lee Dong Ha (Who4mI) Matej Moravec @MacejkoMoravec Mateusz Krzywicki @krzywix Michael (Biscuit) Thomas @social.lol) @biscuit Josh Parnham @joshparnham @RenwaX23 Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar)
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Ventura | <13.7.3 | 13.7.3 |
macOS | <15.3 | 15.3 |
Apple macOS | <14.7.3 | 14.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24183 is categorized as a high-severity vulnerability due to potential exploitation leading to denial of service.
To fix CVE-2025-24183, users should update their affected macOS versions to the latest available releases.
CVE-2025-24183 affects macOS Ventura up to version 13.7.3, macOS Sequoia up to version 15.3, and macOS Sonoma up to version 14.7.3.
CVE-2025-24183 addresses issues including null pointer dereference, type confusion, and input validation vulnerabilities.
CVE-2025-24183 impacts the AirPlay feature and certain components of AppKit related to memory handling and input validation.