First published: Tue Apr 29 2025(Updated: )
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to leak sensitive user information.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS | <15.4 | |
tvOS | <18.4 | |
macOS Ventura | <13.7.5 | |
Apple iOS, iPadOS, and macOS | <17.7.6 | |
Apple macOS | <14.7.5 | |
Apple iOS and iPadOS | <18.4 | |
visionOS | <2.4 | |
Apple iOS, iPadOS, and macOS | <17.7.6 | |
Apple iOS, iPadOS, and macOS | >=18.0<18.4 | |
iPhone OS | <18.4 | |
macOS | <13.7.5 | |
macOS | >=14.0<14.7.5 | |
macOS | >=15.0<15.4 | |
tvOS | <18.4 | |
visionOS | <2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24270 has been classified as a moderate severity vulnerability due to the potential for sensitive information leakage.
To fix CVE-2025-24270, update your devices to the latest versions: macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4, or visionOS 2.4.
CVE-2025-24270 affects Apple devices running macOS Sequoia, tvOS, macOS Ventura, iPadOS, macOS Sonoma, iOS, and visionOS.
CVE-2025-24270 requires an attacker to be on the local network to exploit the vulnerability.
CVE-2025-24270 could potentially leak sensitive user information from affected devices.