• News/
  • https://www.darkreading.com/endpoint-security/apple-patches-actively-exploited-zero-day-vulnerability

Apple Patches Actively Exploited Zero-Day Vulnerability

Dark Reading
·
Kristina Beek
·
Published Jan 27, 2025
·
Updated

NEWS BRIEF In its latest security update for users, Apple has released a patch for a zero-day vulnerability tracked as CVE-2025-24085 (no CVSS score assigned yet). The vulnerability, not yet added to the National Vulnerability Database (NVD), can be found in iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. As a privileged escalation security flaw, it is located in Apple's Core Media framework. The bug is being actively exploited in the wild. The Core Media framework, according to Apple, is "the media pipeline used by AVFoundation and other high-level media frameworks found on Apple platforms." It allows users to process media samples as well as manage queues of media data. This patch comes in the form of iOS 18.3, which fixes 28 other vulnerabilities as well. Apple has yet to divulge many details about any of the issues that have been patched by this update, likely to prevent attackers from exploiting them before users can apply the necessary fix. Impacted devices from this bug include: iPhone XS and later Apple Watch Series 6 and later macOS Sequoia Apple TV HD and Apple TV 4K (all models) iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later Though the tech giant has disclosed that "Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2," it has not published ...

Read full article

Affected Software

12 affected components
Apple iOS
Apple iPadOS
Apple macOS
Apple tvOS
Apple WatchOS
Apple visionOS
Apple iOS=18.3
Apple iPadOS=18.3
Apple macOS
Apple tvOS
Apple WatchOS
Apple visionOS
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Apple's recent security update that addresses an actively exploited zero-day vulnerability.

2

What specific zero-day vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2025-24085.

3

Which Apple operating systems are affected by the vulnerability?

The affected operating systems include Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS.

4

What is the severity of the vulnerability as described in the article?

The CVSS score for this vulnerability has not yet been assigned.

5

Has the vulnerability been added to the National Vulnerability Database?

No, the vulnerability has not yet been added to the National Vulnerability Database.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203