CVE-2025-24141
Published Jan 27, 2025
·Updated
Accessibility. An authentication issue was addressed with improved state management.
Credit
Abhay Kailasia@@abhay_kailasia(C), Uri Katz (Oligo Security), Minghao Lin@@Y1nKoc(Zhejiang University), babywu(Zhejiang University), (Zhejiang University), Xingwei Lin(Zhejiang University), Google Threat Analysis Group, Desmond(Trend Micro Zero Day Initiative), Pwn2car & Rotiple (HyeongSeok Jang)(Trend Micro Zero Day Initiative), CVE-2025-24085, Song Hyun Bae@@bshyuunn, Lee Dong Ha (Who4mI), Wang Yu(Cyberserval), Denis Tokarev@@illusionofcha0s, Zikan Wang@@Lakr233, DongJun Kim@@smlijun, JongSeong Kim in Enki WhiteHat@@nevul37, D4m0n, Mateusz Krzywicki@@krzywix, an anonymous researcher, pattern-f@@pattern_F_, Michael (Biscuit) Thomas @social.lol)@@biscuit, Guilherme Rambo(Best Buddy Apps), Ivan Fratric(Google Project Zero), Hichem Maloufi, Hakim Boukhadra, Mickey Jin@@patch1t, mastersplinter, Jason Gendron@@gendron_jason, 이준성 (Junsung Lee), @@RenwaX23, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Kirin@@Pwnrin, Q1IQ@@q1iqF(NUS CuriOSity), P1umer@@p1umer(Imperial Global Singapore), linjy(HKUS3Lab), chluo(WHUSecLab), Johan Carlsson (joaxcar)
Affected Software
6 affected componentsFixes available
Apple iOS and iPadOS<18.3
Apple iOS, iPadOS, and macOS<18.3
Apple iOS, iPadOS, and macOS<18.3
iPhone OS<18.3
Apple iOS and iPadOS<18.3
18.3
Apple iOS, iPadOS, and macOS<18.3
18.3
Event History
Jan 27, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24141?
CVE-2025-24141 is considered a high severity vulnerability due to its potential to allow unauthorized access to sensitive data on unlocked devices.
2
How do I fix CVE-2025-24141?
To fix CVE-2025-24141, update your device to iOS 18.3 or iPadOS 18.3.
3
What type of vulnerability is CVE-2025-24141?
CVE-2025-24141 is an authentication issue related to state management.
4
Who is affected by CVE-2025-24141?
CVE-2025-24141 affects users of Apple iOS and iPadOS versions prior to 18.3.
5
What devices are impacted by CVE-2025-24141?
CVE-2025-24141 impacts devices running Apple iOS and iPadOS versions before 18.3.