CVE-2025-24143: Input Validation
Accessibility. An authentication issue was addressed with improved state management.
Other sources
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
AppKit. The issue was addressed with additional permissions checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.46.6-1~deb11u1Fixed in 2.46.6-1~deb12u1Fixed in 2.46.6-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.46.6-1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.3 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 18.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24141
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24137
- CVE-2025-24127
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24111
- CVE-2025-24086
- CVE-2025-24144
- CVE-2025-24107
- CVE-2025-24159
- CVE-2025-24117
- CVE-2025-24091
- CVE-2025-24166
- CVE-2025-24104
- CVE-2024-9956
- CVE-2025-24128
- CVE-2025-24113
- CVE-2025-24149
- CVE-2025-24145
- CVE-2025-24154
- CVE-2025-24143
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24150
- CVE-2025-24184
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-31262
- CVE-2025-24189
- CVE-2025-24169
- CVE-2025-24087
- CVE-2025-24112
- CVE-2025-24100
- CVE-2025-24109
- CVE-2025-24114
- CVE-2025-24121
- CVE-2025-24122
- CVE-2025-24106
- CVE-2025-24102
- CVE-2025-24134
- CVE-2025-24140
- CVE-2025-24174
- CVE-2025-24118
- CVE-2025-24119
- CVE-2025-24094
- CVE-2025-24115
- CVE-2025-24116
- CVE-2025-24136
- CVE-2025-24101
- CVE-2025-24096
- CVE-2025-24099
- CVE-2025-24130
- CVE-2025-24183
- CVE-2025-24146
- CVE-2025-24103
- CVE-2025-24108
- CVE-2025-24185
- CVE-2025-24139
- CVE-2025-24151
- CVE-2025-24152
- CVE-2025-24153
- CVE-2025-24138
- CVE-2025-24176
- CVE-2025-24135
- CVE-2025-24092
- CVE-2025-24155
- CVE-2025-24120
- CVE-2025-24156
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-31185
Frequently Asked Questions
What is the severity of CVE-2025-24143?
CVE-2025-24143 has been classified with high severity due to multiple authentication and input validation issues.
How do I fix CVE-2025-24143?
To fix CVE-2025-24143, update affected Apple software to the latest versions listed in the vulnerability details.
Which Apple products are affected by CVE-2025-24143?
CVE-2025-24143 affects Apple macOS Sequoia, Safari, iOS, iPadOS, and visionOS versions up to specific release thresholds.
What types of issues does CVE-2025-24143 address?
CVE-2025-24143 addresses authentication issues, input validation problems, null pointer dereferences, and type confusion issues.
Is there a workaround for CVE-2025-24143 if I cannot update?
There are no documented workarounds for CVE-2025-24143, and it is recommended to update affected software as soon as possible.