CVE-2025-24091: Race Condition
Accessibility. An authentication issue was addressed with improved state management.
Other sources
Accounts. A logic issue was addressed with improved file handling.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-54488
- CVE-2024-54486
- CVE-2024-54500
- CVE-2024-54468
- CVE-2024-54494
- CVE-2024-54510
- CVE-2024-44245
- CVE-2024-44201
- CVE-2024-45490
- CVE-2025-24091
- CVE-2024-44225
- CVE-2024-54492
- CVE-2024-44246
- CVE-2024-54501
- CVE-2024-54485
- CVE-2024-54479
- CVE-2024-54505
- CVE-2025-24141
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24137
- CVE-2025-24127
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24184
- CVE-2025-24111
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-24086
- CVE-2025-24144
- CVE-2025-24107
- CVE-2025-24159
- CVE-2025-24117
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-24104
- CVE-2025-31262
- CVE-2024-9956
- CVE-2025-31185
- CVE-2025-24128
- CVE-2025-24113
- CVE-2025-24149
- CVE-2025-24145
- CVE-2025-24154
- CVE-2025-24189
- CVE-2025-24143
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24150
Frequently Asked Questions
What is the severity of CVE-2025-24091?
CVE-2025-24091 is considered a moderate severity vulnerability due to the potential for denial-of-service and impersonation of sensitive notifications.
How do I fix CVE-2025-24091?
To mitigate CVE-2025-24091, update to iOS 18.3 or iPadOS 18.3, or iPadOS 17.7.3.
What types of devices are affected by CVE-2025-24091?
CVE-2025-24091 affects Apple devices running iOS versions up to 18.3 and iPadOS versions up to 18.3 and 17.7.3.
What can exploit CVE-2025-24091?
An attacker could potentially exploit CVE-2025-24091 to impersonate system notifications or cause a denial-of-service.
Is this vulnerability fixed in earlier versions of iOS?
No, CVE-2025-24091 is not fixed in versions prior to iOS 18.3 and iPadOS 17.7.3.