• News/
  • https://www.theregister.com/2025/01/28/apple_cve_2025_24085/

Apple plugs security hole in its iThings that's already been exploited in iOS

The Register
·
Jessica Lyons
·
Published Jan 28, 2025
·
Updated

Apple has plugged a security hole in the software at the heart of its iPhones, iPads, Vision Pro goggles, Apple TVs and macOS Sequoia Macs, warning some miscreants have already exploited the bug. The vulnerability, tracked as CVE-2025-24085, is a use-after-free() flaw in the CoreMedia component common across iOS, macOS, and so forth that the iGiant says it fixed with improved memory management. CoreMedia is essentially the engine behind how Apple gear deals with audio and video. We don't have much — or, really, any — information about how the bug is being abused in attacks and by whom, other than it can be used by a rogue app on someone's device to gain more control over the system and that it's been used against iOS devices. While more details will likely leak out in the coming days, as of now we know the vulnerability was exploited as a zero-day, making it Apple's first of 2025. "A malicious application may be able to elevate privileges," Apple noted in five of its Monday security updates. "Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2." Apple didn't credit a security researcher or group with finding CVE-2025-24085, and it's still awaiting a CVSS severity rating plus additional CVE record details. As details of the vulnerability are known to some, and patches are now available, it's wise to apply the fix to all affected devices in case someone decides to port the exploit from iOS to other Apple OSes to us...

Read full article

Affected Software

12 affected components
Apple iOS
Apple macOS=Sequoia
Apple tvOS
Apple visionOS
Apple WatchOS
Apple Safari
Apple iOS
Apple macOS=Sequoia
Apple CoreMedia
Apple iPadOS
Apple Vision Pro
Apple Apple TV
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security vulnerability in Apple's software that has already been exploited.

2

What specific products are affected by this security vulnerability?

The affected products include iPhones, iPads, Vision Pro goggles, Apple TVs, and macOS Sequoia Macs.

3

What type of exploitation has occurred related to this security issue?

The article warns that some malicious actors have already exploited the bug.

4

What versions of Apple's operating systems are mentioned to have the vulnerability?

The vulnerability affects iOS, macOS Sequoia, tvOS, visionOS, watchOS, and Safari.

5

What has Apple done in response to this security threat?

Apple has released a patch to fix the security hole in its software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203