CVE-2025-24112: Input Validation
Published Jan 27, 2025
·Updated
AirPlay. A null pointer dereference was addressed with improved input validation.
Credit
Uri Katz (Oligo Security), Mickey Jin@@patch1t, D4m0n, Kirin@@Pwnrin, Bohdan Stasiuk@@Bohdan_Stasiuk, Minghao Lin@@Y1nKoc(Zhejiang University), babywu(Zhejiang University), (Zhejiang University), Xingwei Lin(Zhejiang University), Wang Yu(Cyberserval), Google Threat Analysis Group, Desmond(Trend Micro Zero Day Initiative), Pwn2car & Rotiple (HyeongSeok Jang)(Trend Micro Zero Day Initiative), CVE-2025-24085, Song Hyun Bae@@bshyuunn, Lee Dong Ha (Who4mI), Matej Moravec@@MacejkoMoravec, Arsenii Kostromin (0x3c3e), Joshua Jones, DongJun Kim@@smlijun, JongSeong Kim in Enki WhiteHat@@nevul37, Mateusz Krzywicki@@krzywix, Joseph Ravichandran@@0xjprx(MIT CSAIL), an anonymous researcher, pattern-f@@pattern_F_, Michael (Biscuit) Thomas @social.lol)@@biscuit, Ivan Fratric(Google Project Zero), 风(binary_fmyy), Minghao Lin@(Y1nKoc), Pedro Tôrres@@t0rr3sp3dr0, Josh Parnham@@joshparnham, 神罚@@Pwnrin, @@RenwaX23, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Zhongquan Li@@Guluisacat, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Junsung Lee, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Yann GASCUEL(Alter Solutions), Adam M., Q1IQ@@q1iqF(NUS CuriOSity), P1umer@@p1umer(Imperial Global Singapore), linjy(HKUS3Lab), chluo(WHUSecLab), Johan Carlsson (joaxcar), PixiePoint Security, CertiK SkyFall Team, Pwn2car & Rotiple(HyeongSeok Jang)(Trend Micro Zero Day Initiative), Anonymous(Trend Micro Zero Day Initiative), Yiğit Can YILMAZ@@yilmazcanyigit, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Eric Dorphy(Twin Cities App Dev LLC), jioundai(360 Vulnerability Research Institute), chen fengjiao(HBC)
Affected Software
6 affected componentsFixes available
apple macOS Sequoia
apple macOS Sonoma
Apple macOS<14.7.3
Apple macOS>=15.0<15.3
apple macOS Sequoia<15.3
15.3
apple macOS Sonoma<14.7.3
14.7.3
Event History
Jan 27, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24112?
CVE-2025-24112 has a severity rating that indicates it can lead to remote code execution due to memory and input validation issues.
2
How do I fix CVE-2025-24112?
To fix CVE-2025-24112, update your macOS Sequoia to version 15.3 or macOS Sonoma to version 14.7.3.
3
What types of issues are addressed in CVE-2025-24112?
CVE-2025-24112 addresses null pointer dereference, type confusion, and input validation issues.
4
Which versions of macOS are affected by CVE-2025-24112?
CVE-2025-24112 affects Apple macOS Sequoia and macOS Sonoma prior to specified versions.
5
Is CVE-2025-24112 a critical vulnerability?
Yes, CVE-2025-24112 is considered critical as it may allow an attacker to execute arbitrary code on affected systems.