Apple has plugged a security hole in the software at the heart of its iPhones, iPads, Vision Pro goggles, Apple TVs and macOS Sequoia Macs, warning some miscreants have already exploited the bug. The vulnerability, tracked as CVE-2025-24085, is a use-after-free() flaw in the CoreMedia component common across iOS, macOS, and so forth that the iGiant says it fixed with improved memory management. CoreMedia is essentially the engine behind how Apple gear deals with audio and video. We don't have much — or, really, any — information about how the bug is being abused in attacks and by whom, other than it can be used by a rogue app on someone's device to gain more control over the system and that it's been used against iOS devices. While more details will likely leak out in the coming days, as of now we know the vulnerability was exploited as a zero-day, making it Apple's first of 2025. "A malicious application may be able to elevate privileges," Apple noted in five of its Monday security updates. "Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2." Apple didn't credit a security researcher or group with finding CVE-2025-24085, and it's still awaiting a CVSS severity rating plus additional CVE record details. As details of the vulnerability are known to some, and patches are now available, it's wise to apply the fix to all affected devices in case someone decides to port the exploit from iOS to other Apple OSes to us...
Apple plugs security hole in its iThings that's already been exploited in iOS
The Register
·Jessica Lyons
·Published Jan 28, 2025
·Updated
Affected Software
12 affected components
Apple iOS
Apple macOS=Sequoia
Apple tvOS
Apple visionOS
Apple WatchOS
Apple Safari
Apple iOS
Apple macOS=Sequoia
Apple CoreMedia
Apple iPadOS
Apple Vision Pro
Apple Apple TV
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a security vulnerability in Apple's software that has already been exploited.
2
What specific products are affected by this security vulnerability?
The affected products include iPhones, iPads, Vision Pro goggles, Apple TVs, and macOS Sequoia Macs.
3
What type of exploitation has occurred related to this security issue?
The article warns that some malicious actors have already exploited the bug.
4
What versions of Apple's operating systems are mentioned to have the vulnerability?
The vulnerability affects iOS, macOS Sequoia, tvOS, visionOS, watchOS, and Safari.
5
What has Apple done in response to this security threat?
Apple has released a patch to fix the security hole in its software.