CVE-2025-24159: Use After Free
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to execute arbitrary code with kernel privileges.
Other sources
Accessibility. An authentication issue was addressed with improved state management.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. An input validation issue was addressed.
— Apple
AirPlay. The issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24085
- CVE-2025-24137
- CVE-2025-24145
- CVE-2025-24107
- CVE-2025-24128
- CVE-2025-24126
- CVE-2025-24129
- CVE-2025-24131
- CVE-2025-24160
- CVE-2025-24161
- CVE-2025-24163
- CVE-2025-24123
- CVE-2025-24124
- CVE-2025-24086
- CVE-2025-24159
- CVE-2025-24117
- CVE-2025-24149
- CVE-2025-24158
- CVE-2025-24162
- CVE-2025-24179
- CVE-2025-24127
- CVE-2025-24184
- CVE-2025-24111
- CVE-2025-24144
- CVE-2024-55549
- CVE-2025-24855
- CVE-2025-31262
- CVE-2025-24189
- CVE-2025-24113
- CVE-2025-24154
- CVE-2025-24143
- CVE-2025-24102
- CVE-2024-54478
- CVE-2025-24118
- CVE-2025-24104
- CVE-2024-54497
- CVE-2025-24177
- CVE-2025-24087
- CVE-2025-24112
- CVE-2025-24100
- CVE-2025-24109
- CVE-2025-24114
- CVE-2025-24121
- CVE-2025-24122
- CVE-2025-24106
- CVE-2025-24134
- CVE-2025-24140
- CVE-2025-24174
- CVE-2025-24119
- CVE-2025-24094
- CVE-2025-24115
- CVE-2025-24116
- CVE-2025-24136
- CVE-2025-24101
- CVE-2025-24096
- CVE-2025-24099
- CVE-2025-24130
- CVE-2025-24169
- CVE-2025-24183
- CVE-2025-24146
- CVE-2025-24103
- CVE-2025-24108
- CVE-2025-24185
- CVE-2025-24139
- CVE-2025-24151
- CVE-2025-24152
- CVE-2025-24153
- CVE-2025-24138
- CVE-2025-24176
- CVE-2025-24135
- CVE-2025-24092
- CVE-2025-24155
- CVE-2025-24150
- CVE-2025-24120
- CVE-2025-24156
- CVE-2024-54509
- CVE-2024-44172
- CVE-2025-24093
- CVE-2024-44243
- CVE-2025-31242
- CVE-2025-31248
- CVE-2025-43374
- CVE-2025-24141
- CVE-2025-24089
- CVE-2025-24090
- CVE-2025-24091
- CVE-2024-9956
- CVE-2025-31185
Frequently Asked Questions
What is the severity of CVE-2025-24159?
CVE-2025-24159 has a significant severity level as it allows an app to execute arbitrary code with kernel privileges.
How do I fix CVE-2025-24159?
To fix CVE-2025-24159, update your device to the latest versions: iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3, or corresponding updates for watchOS and tvOS.
What devices are affected by CVE-2025-24159?
CVE-2025-24159 affects devices running iPadOS 17.7.4 and earlier, macOS Sonoma 14.7.3 and earlier, visionOS 2.3 and earlier, iOS 18.3 and earlier, as well as older versions of watchOS and tvOS.
What type of issue is CVE-2025-24159?
CVE-2025-24159 is classified as a validation issue that could lead to arbitrary code execution.
Is CVE-2025-24159 related to authentication bypass?
While CVE-2025-24159 primarily deals with code execution, it has implications for security measures, including potential authentication bypass risks.