CVE-2025-24085: Apple Multiple Products Use-After-Free Vulnerability
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
Other sources
Accessibility. An authentication issue was addressed with improved state management.
— Apple
AccountPolicy. This issue was addressed by removing the vulnerable code.
— Apple
Accounts. This issue was addressed with improved data access restriction.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 11.3 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 13.7.5 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 17.7.6 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.3 - Upgrade
Upgrade
macOS Sonomato a version that resolves this vulnerability.Fixed in 14.7.5 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.7.5 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.3
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24137
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24086
- CVE-2025-24107
- CVE-2025-24159
- CVE-2025-24117
- CVE-2025-24149
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-31200
- CVE-2025-31201
- CVE-2025-24200
- CVE-2025-24201
- CVE-2025-24179
- CVE-2025-24127
- CVE-2025-24184
- CVE-2025-24111
- CVE-2025-24144
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-31262
- CVE-2025-24189
- CVE-2025-24113
- CVE-2025-24154
- CVE-2025-24143
- CVE-2025-24234
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24206
- CVE-2025-24276
- CVE-2024-40864
- CVE-2025-24272
- CVE-2025-24231
- CVE-2025-24233
- CVE-2025-30443
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-30460
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31191
- CVE-2025-24170
- CVE-2025-24277
- CVE-2024-9681
- CVE-2025-31189
- CVE-2025-24255
- CVE-2025-24267
- CVE-2025-30456
- CVE-2025-31187
- CVE-2025-30462
- CVE-2025-24199
- CVE-2025-30447
- CVE-2025-24256
- CVE-2025-24273
- CVE-2025-30464
- CVE-2025-24210
- CVE-2025-24249
- CVE-2025-24229
- CVE-2025-24235
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-24148
- CVE-2025-24195
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-31264
- CVE-2025-24172
- CVE-2025-30450
- CVE-2025-30470
- CVE-2025-24232
- CVE-2025-24246
- CVE-2025-24261
- CVE-2025-24164
- CVE-2025-30446
- CVE-2025-24259
- CVE-2025-30424
- CVE-2025-24173
- CVE-2025-30452
- CVE-2025-24181
- CVE-2025-30471
- CVE-2025-24250
- CVE-2025-30438
- CVE-2025-31194
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24139
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-30444
- CVE-2025-24228
- CVE-2025-24260
- CVE-2025-24254
- CVE-2024-54533
- CVE-2025-24207
- CVE-2025-31261
- CVE-2025-24253
- CVE-2025-30449
- CVE-2025-31188
- CVE-2025-24240
- CVE-2025-24278
- CVE-2025-30457
- CVE-2025-24279
- CVE-2025-24247
- CVE-2025-24241
- CVE-2025-24266
- CVE-2025-24265
- CVE-2025-24157
- CVE-2025-31198
- CVE-2025-24221
- CVE-2025-31203
- CVE-2025-30426
- CVE-2025-30428
- CVE-2025-30425
- CVE-2025-24216
- CVE-2025-24264
- CVE-2025-30427
- CVE-2025-24209
- CVE-2024-54543
- CVE-2024-54534
- CVE-2024-54508
- CVE-2024-54502
- CVE-2025-24087
- CVE-2025-24112
- CVE-2025-24100
- CVE-2025-24109
- CVE-2025-24114
- CVE-2025-24121
- CVE-2025-24122
- CVE-2025-24106
- CVE-2025-24102
- CVE-2025-24134
- CVE-2025-24140
- CVE-2025-24174
- CVE-2025-24118
- CVE-2025-24119
- CVE-2025-24094
- CVE-2025-24115
- CVE-2025-24116
- CVE-2025-24136
- CVE-2025-24101
- CVE-2025-24096
- CVE-2025-24099
- CVE-2025-24130
- CVE-2025-24169
- CVE-2025-24183
- CVE-2025-24146
- CVE-2025-24128
- CVE-2025-24103
- CVE-2025-24108
- CVE-2025-24185
- CVE-2025-24151
- CVE-2025-24152
- CVE-2025-24153
- CVE-2025-24138
- CVE-2025-24176
- CVE-2025-24135
- CVE-2025-24145
- CVE-2025-24092
- CVE-2025-24155
- CVE-2025-24150
- CVE-2025-24120
- CVE-2025-24156
- CVE-2025-24141
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-24091
- CVE-2025-24104
- CVE-2024-9956
- CVE-2025-31185
- CVE-2025-24097
- CVE-2025-43465
- CVE-2025-24236
- CVE-2025-30454
- CVE-2025-30455
- CVE-2025-30431
- CVE-2025-24196
- CVE-2025-24280
- CVE-2025-31183
- CVE-2025-24165
- CVE-2025-31195
Frequently Asked Questions
What is the severity of CVE-2025-24085?
CVE-2025-24085 is a high-severity vulnerability that may allow a malicious application to elevate privileges.
How do I fix CVE-2025-24085?
To fix CVE-2025-24085, update your devices to the latest versions: visionOS 2.3, iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, or tvOS 18.3.
What devices are affected by CVE-2025-24085?
CVE-2025-24085 affects multiple devices including Apple visionOS, iOS, iPadOS, macOS Sequoia, watchOS, and tvOS.
What type of issue is CVS-2025-24085?
CVE-2025-24085 is classified as a use after free vulnerability that could lead to privilege escalation.
Is there any active exploitation reported for CVE-2025-24085?
Yes, Apple is aware of a report indicating that CVE-2025-24085 may have been actively exploited.