CVE-2025-24149: Input Validation
Accessibility. An authentication issue was addressed with improved state management.
Other sources
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to disclosure of user information.
— MITRE
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24137
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24085
- CVE-2025-24086
- CVE-2025-24107
- CVE-2025-24159
- CVE-2025-24117
- CVE-2025-24149
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24127
- CVE-2025-24102
- CVE-2024-54478
- CVE-2025-24118
- CVE-2025-24166
- CVE-2025-24104
- CVE-2024-54497
- CVE-2025-24141
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24111
- CVE-2025-24144
- CVE-2025-24091
- CVE-2024-9956
- CVE-2025-24128
- CVE-2025-24113
- CVE-2025-24145
- CVE-2025-24154
- CVE-2025-24143
- CVE-2025-24150
- CVE-2025-24184
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-31262
- CVE-2025-24189
- CVE-2025-24087
- CVE-2025-24112
- CVE-2025-24100
- CVE-2025-24109
- CVE-2025-24114
- CVE-2025-24121
- CVE-2025-24122
- CVE-2025-24106
- CVE-2025-24134
- CVE-2025-24140
- CVE-2025-24174
- CVE-2025-24119
- CVE-2025-24094
- CVE-2025-24115
- CVE-2025-24116
- CVE-2025-24136
- CVE-2025-24101
- CVE-2025-24096
- CVE-2025-24099
- CVE-2025-24130
- CVE-2025-24169
- CVE-2025-24183
- CVE-2025-24146
- CVE-2025-24103
- CVE-2025-24108
- CVE-2025-24185
- CVE-2025-24139
- CVE-2025-24151
- CVE-2025-24152
- CVE-2025-24153
- CVE-2025-24138
- CVE-2025-24176
- CVE-2025-24135
- CVE-2025-24092
- CVE-2025-24155
- CVE-2025-24120
- CVE-2025-24156
- CVE-2024-44172
- CVE-2025-24093
- CVE-2025-31242
- CVE-2025-31248
- CVE-2025-43374
- CVE-2024-54509
- CVE-2024-44243
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-31185
Frequently Asked Questions
What is the severity of CVE-2025-24149?
CVE-2025-24149 is rated as high severity due to its potential to exploit authentication and input validation vulnerabilities.
How do I fix CVE-2025-24149?
To fix CVE-2025-24149, update your affected Apple devices to the latest available software version as listed in the security advisory.
Which products are affected by CVE-2025-24149?
CVE-2025-24149 affects Apple iOS, iPadOS, macOS Ventura, macOS Sonoma, macOS Sequoia, visionOS, watchOS, and tvOS up to specific versions as specified.
What issues are addressed in CVE-2025-24149?
CVE-2025-24149 addresses multiple vulnerabilities including authentication issues, null pointer dereferences, type confusion, and input validation problems.
Is there a workaround for CVE-2025-24149?
There is no specific workaround mentioned for CVE-2025-24149, and the best approach is to apply the necessary updates promptly.