CVE-2025-24159: Use After Free
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to execute arbitrary code with kernel privileges.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24159?
CVE-2025-24159 has a significant severity level as it allows an app to execute arbitrary code with kernel privileges.
How do I fix CVE-2025-24159?
To fix CVE-2025-24159, update your device to the latest versions: iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3, or corresponding updates for watchOS and tvOS.
What devices are affected by CVE-2025-24159?
CVE-2025-24159 affects devices running iPadOS 17.7.4 and earlier, macOS Sonoma 14.7.3 and earlier, visionOS 2.3 and earlier, iOS 18.3 and earlier, as well as older versions of watchOS and tvOS.
What type of issue is CVE-2025-24159?
CVE-2025-24159 is classified as a validation issue that could lead to arbitrary code execution.
Is CVE-2025-24159 related to authentication bypass?
While CVE-2025-24159 primarily deals with code execution, it has implications for security measures, including potential authentication bypass risks.