Apple has released security updates to fix this year's first zero-day vulnerability, tagged as actively exploited in attacks targeting iPhone users. The zero-day fixed today is tracked as CVE-2025-24085 [iOS/iPadOS, macOS, tvOS, watchOS, visionOS] and is a privilege escalation security flaw in Apple's Core Media framework. "A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2," Apple said today. According to the company's official documentation, Core Media "defines the media pipeline used by AVFoundation and other high-level media frameworks found on Apple platforms." Apple has fixed CVE-2024-23222 with improved memory management in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, visionOS 2.3, and tvOS 18.3. The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including: Apple has yet to attribute the discovery of this security vulnerability to a security researcher and has not published details regarding attacks, even though it disclosed that it is exploited in the wild. While this zero-day bug was likely only exploited in targeted attacks, it is highly advised to install today's security updates as soon as possible to block potentially ongoing attack attempts. Last year, the company fixed a total of six zero-days, the first in January, two in March, a fourth in May, and two more in Novemb...
Apple fixes this year’s first actively exploited zero-day bug
BleepingComputer
·Sergiu Gatlan
·Published Jan 27, 2025
·Updated
Affected Software
12 affected components
Apple Core Media=iOS 17.1
Apple Core Media=iPadOS 17.1
Apple Core Media=macOS
Apple Core Media=tvOS
Apple Core Media=watchOS
Apple Core Media=visionOS
Apple iOS
Apple iPadOS
Apple macOS=Sequoia 15.3
Apple tvOS=18.3
Apple WatchOS=11.3
Apple visionOS=2.3
Frequently Asked Questions
1
What is the significance of CVE-2025-24085 mentioned in the article?
CVE-2025-24085 is an actively exploited zero-day vulnerability affecting various Apple devices including iPhones.
2
Which Apple operating systems are impacted by the zero-day vulnerability?
The zero-day vulnerability affects iOS, iPadOS, macOS, tvOS, watchOS, and visionOS.
3
How has Apple responded to the zero-day vulnerability?
Apple has released security updates to fix the zero-day vulnerability to protect users from potential attacks.
4
When was the zero-day vulnerability first discovered?
The vulnerability was recognized as a zero-day exploit earlier this year and has been actively targeted in attacks.
5
What should users do to mitigate the risk from this vulnerability?
Users are advised to update their devices to the latest software versions provided by Apple to ensure security.