CVE-2025-24113: Use After Free
Published Jan 27, 2025
·Updated
Accessibility. A logging issue was addressed with improved data redaction.
Credit
Ivan Fratric(Google Project Zero), Hichem Maloufi, Hakim Boukhadra, mastersplinter, @@RenwaX23, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Kirin@@Pwnrin, an anonymous researcher, Q1IQ@@q1iqF(NUS CuriOSity), P1umer@@p1umer(Imperial Global Singapore), linjy(HKUS3Lab), chluo(WHUSecLab), Johan Carlsson (joaxcar), pattern-f@@pattern_F_, Michael (Biscuit) Thomas @social.lol)@@biscuit, Mickey Jin@@patch1t, Mateusz Krzywicki@@krzywix, Uri Katz (Oligo Security), Minghao Lin@@Y1nKoc(Zhejiang University), babywu(Zhejiang University), (Zhejiang University), Xingwei Lin(Zhejiang University), Google Threat Analysis Group, Desmond(Trend Micro Zero Day Initiative), Pwn2car & Rotiple (HyeongSeok Jang)(Trend Micro Zero Day Initiative), CVE-2025-24085, Song Hyun Bae@@bshyuunn, Lee Dong Ha (Who4mI), Wang Yu(Cyberserval), DongJun Kim@@smlijun, JongSeong Kim in Enki WhiteHat@@nevul37, D4m0n, Josh Parnham@@joshparnham, Jaydev Ahire, Syarif Muhammad Sajjad, Alexander Heinrich@@Sn0wfreeze, SEEMOO, TU Darmstadt & Mathy Vanhoef@@vanhoefm, Jeroen Robben@@RobbenJeroen, DistriNet, KU Leuven, Vsevolod Kokorin (Slonser)(Solidlab), Gary Kwong, Paul Bakker(ParagonERP), Francisco Alonso@@revskills, Muhammad Zaid Ghifari (Mr.ZheeV), Kalimantan Utara, rheza@@ginggilBesel, Martin Kreichgauer(Google Chrome), Lehan Dilusha@@zafer, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Yutong Xiu@@Sou1gh0st, Denis Tokarev@@illusionofcha0s, CVE-2024-9681, LFY@@secsys(Fudan University), Anonymous(Trend Micro Zero Day Initiative), Michael (Biscuit) Thomas - @social.lol@@biscuit, Ian Beer(Google Project Zero), CVE-2025-27113, CVE-2024-56171, Jimmy, Jax Reissner, Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Luyi Xing(Indiana University Bloomington), Andrew James Gonzalez, Richard Hyunho Im with routezero.security@@richeeta, YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Minghao Lin@@Y1nKoc, Apple, Lukas Bernhard, Tashita Software Security, Xiangwei Zhang(Tencent Security YUNDING LAB), Brendon Tiszka(Google Project Zero), Wojciech Regula(SecuRing), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Bohdan Stasiuk@@bohdan_stasiuk, Dominik Rath, Ian Mckay@@iann0036, wac(Trend Micro Zero Day Initiative), Csaba Fitzl@@theevilbit(Kandji), Nolan Astrein(Kandji), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Gergely Kalman@@gergely_kalman, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Pietro Francesco Tirenna(Shielder), Davide Silvetti(Shielder), Abdel Adim Oisfi(Shielder), luckyu@@uuulucky, Rodolphe BRUNETTI@@eisw0lf, Andr.Ess, Manuel Fernandez (Stackhopper Security), ABC Research s.r.o., Murray Mike, mzzzz__, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, Ye Zhang@@VAR10CK(Baidu Security), Dave G.(Supernetworks), Koh M. Nakagawa@@tsunek0h(FFRI Security Inc), Joseph Ravichandran@@0xjprx(MIT CSAIL), Kenneth Chew, CVE-2024-48958, Paweł Płatek (Trail(Bits), Alex Radocea(Supernetworks), 风沐云烟@@binary_fmyy, Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Diamant Osmani & Valdrin Haliti [Kosovë], dbpeppe, Solitechworld, Pwn2car, Mickey Jin@@patch1t(Kandji), (Kandji), Pedro Tôrres@@t0rr3sp3dr0, Noah Gregory (wts.dev), CVE-2023-27043, Yiğit Can YILMAZ@@yilmazcanyigit, Arsenii Kostromin (0x3c3e), Halle Winkler, Politepix theoffcuts.org, Dolf Hoegaerts, Michiel Devliegere, K宝@@Pwnrin, Tong Liu@@Lyutoon_, 风(binary_fmyy), F00L, zbleet(QI), Cristian Dinca(Computer Science), Romania, 风沐云烟 (binary_fmyy), Kirin, FlowerCode, Zhongquan Li@@Guluisacat, Pedro José Pereira Vieito / pvieito.com)@@pvieito, PixiePoint Security, Andreas Hegenberg (folivora.AI GmbH), Ron Masas(BREAKPOINT), Zhongcheng Li(IES Red Team of ByteDance), Bohdan Stasiuk@@Bohdan_Stasiuk, Matej Moravec@@MacejkoMoravec, Joshua Jones, Minghao Lin@(Y1nKoc), 神罚@@Pwnrin, Junsung Lee, Yann GASCUEL(Alter Solutions), Adam M., Florian Draschbacher, Dalibor Milanovic, Abhay Kailasia@@abhay_kailasia(C), Chi Yuan Chang(ZUSO ART), taikosoup, Zikan Wang@@Lakr233, Guilherme Rambo(Best Buddy Apps), Jason Gendron@@gendron_jason, 이준성 (Junsung Lee)
Affected Software
17 affected componentsFixes available
Apple macOS Sequoia
Apple Safari
Apple iOS
Apple iPadOS
Apple visionOS
Apple Safari<18.3
Apple iPadOS<18.3
Apple iPhone OS<18.3
Apple macOS<15.3
Apple visionOS<2.3
Apple iOS<18.3
18.3
Apple iPadOS<18.3
18.3
Apple macOS Sequoia<15.3
15.3
Apple visionOS<2.3
2.3
Apple Safari<18.3
18.3
Apple iPadOS<17.7.6
17.7.6
Apple WatchOS<11.4
11.4
Event History
Jan 27, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Mar 31, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Apr 1, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24113?
CVE-2025-24113 is classified as a moderate severity vulnerability affecting Apple products.
2
How do I fix CVE-2025-24113?
To mitigate CVE-2025-24113, update to the latest versions of affected Apple software, specifically macOS Sequoia 15.3, iOS 18.3, iPadOS 18.3, Safari 18.3, or visionOS 2.3.
3
Which Apple products are affected by CVE-2025-24113?
CVE-2025-24113 affects Apple macOS Sequoia, Safari, iOS, iPadOS, and visionOS.
4
What types of issues are addressed in CVE-2025-24113?
CVE-2025-24113 addresses authentication issues, null pointer dereferences, type confusion, and input validation vulnerabilities.
5
Is there a public reference for CVE-2025-24113?
Details about CVE-2025-24113 are provided by Apple in their official support documentation.