CVE-2025-24163: Input Validation
Published Jan 27, 2025
·Updated
Accessibility. A logging issue was addressed with improved data redaction.
Credit
Uri Katz (Oligo Security), Google Threat Analysis Group, Desmond(Trend Micro Zero Day Initiative), Pwn2car & Rotiple (HyeongSeok Jang)(Trend Micro Zero Day Initiative), CVE-2025-24085, DongJun Kim@@smlijun, JongSeong Kim in Enki WhiteHat@@nevul37, D4m0n, an anonymous researcher, pattern-f@@pattern_F_, Michael (Biscuit) Thomas @social.lol)@@biscuit, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Q1IQ@@q1iqF(NUS CuriOSity), P1umer@@p1umer(Imperial Global Singapore), linjy(HKUS3Lab), chluo(WHUSecLab), Minghao Lin@@Y1nKoc(Zhejiang University), babywu(Zhejiang University), (Zhejiang University), Xingwei Lin(Zhejiang University), Song Hyun Bae@@bshyuunn, Lee Dong Ha (Who4mI), Wang Yu(Cyberserval), Mateusz Krzywicki@@krzywix, Ivan Fratric(Google Project Zero), Mickey Jin@@patch1t, @@RenwaX23, Pwn2car & Rotiple(HyeongSeok Jang)(Trend Micro Zero Day Initiative), Kirin@@Pwnrin, Gary Kwong, Joseph Ravichandran@@0xjprx(MIT CSAIL), Hichem Maloufi, Hakim Boukhadra, Anonymous(Trend Micro Zero Day Initiative), Wojciech Regula(SecuRing), Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Bohdan Stasiuk@@bohdan_stasiuk, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Dominik Rath, Martin Kreichgauer(Google Chrome), Ian Mckay@@iann0036, Yutong Xiu@@Sou1gh0st, Denis Tokarev@@illusionofcha0s, wac(Trend Micro Zero Day Initiative), Csaba Fitzl@@theevilbit(Kandji), Nolan Astrein(Kandji), Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), Gergely Kalman@@gergely_kalman, CVE-2024-9681, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Pietro Francesco Tirenna(Shielder), Davide Silvetti(Shielder), Abdel Adim Oisfi(Shielder), luckyu@@uuulucky, Rodolphe BRUNETTI@@eisw0lf, Andr.Ess, LFY@@secsys(Fudan University), Manuel Fernandez (Stackhopper Security), ABC Research s.r.o., Murray Mike, mzzzz__, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Minghao Lin@@Y1nKoc, Ye Zhang@@VAR10CK(Baidu Security), Dave G.(Supernetworks), Koh M. Nakagawa@@tsunek0h(FFRI Security Inc), Ian Beer(Google Project Zero), Kenneth Chew, CVE-2024-48958, Paweł Płatek (Trail(Bits), CVE-2025-27113, CVE-2024-56171, Alex Radocea(Supernetworks), 风沐云烟@@binary_fmyy, Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Diamant Osmani & Valdrin Haliti [Kosovë], dbpeppe, Solitechworld, Pwn2car, Jimmy, Mickey Jin@@patch1t(Kandji), (Kandji), Pedro Tôrres@@t0rr3sp3dr0, Noah Gregory (wts.dev), CVE-2023-27043, Jaydev Ahire, Syarif Muhammad Sajjad, Yiğit Can YILMAZ@@yilmazcanyigit, Arsenii Kostromin (0x3c3e), Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Luyi Xing(Indiana University Bloomington), Halle Winkler, Politepix theoffcuts.org, Dolf Hoegaerts, Michiel Devliegere, Andrew James Gonzalez, K宝@@Pwnrin, Tong Liu@@Lyutoon_, 风(binary_fmyy), F00L, Richard Hyunho Im with routezero.security@@richeeta, zbleet(QI), Cristian Dinca(Computer Science), Romania, 风沐云烟 (binary_fmyy), Kirin, FlowerCode, Zhongquan Li@@Guluisacat, Pedro José Pereira Vieito / pvieito.com)@@pvieito, Alexander Heinrich@@Sn0wfreeze, SEEMOO, TU Darmstadt & Mathy Vanhoef@@vanhoefm, Jeroen Robben@@RobbenJeroen, DistriNet, KU Leuven, Vsevolod Kokorin (Slonser)(Solidlab), Paul Bakker(ParagonERP), Francisco Alonso@@revskills, rheza@@ginggilBesel, PixiePoint Security, Andreas Hegenberg (folivora.AI GmbH), Ron Masas(BREAKPOINT), Zhongcheng Li(IES Red Team of ByteDance), Bohdan Stasiuk@@Bohdan_Stasiuk, Matej Moravec@@MacejkoMoravec, Joshua Jones, Minghao Lin@(Y1nKoc), Josh Parnham@@joshparnham, 神罚@@Pwnrin, Junsung Lee, Yann GASCUEL(Alter Solutions), Adam M., Johan Carlsson (joaxcar), Michael (Biscuit) Thomas - @social.lol@@biscuit, Lehan Dilusha@@zafer, Apple, Muhammad Zaid Ghifari (Mr.ZheeV), Kalimantan Utara, Florian Draschbacher, Jax Reissner, Dalibor Milanovic, Abhay Kailasia@@abhay_kailasia(C), Chi Yuan Chang(ZUSO ART), taikosoup, CertiK SkyFall Team, Eric Dorphy(Twin Cities App Dev LLC), jioundai(360 Vulnerability Research Institute), chen fengjiao(HBC), Zikan Wang@@Lakr233, Guilherme Rambo(Best Buddy Apps), mastersplinter, Jason Gendron@@gendron_jason, 이준성 (Junsung Lee)
Affected Software
23 affected componentsFixes available
Apple WatchOS<11.3
11.3
Apple iPadOS<17.7.4, >=18.3
Apple macOS Sonoma<14.7.3
Apple visionOS<2.3
Apple iOS<18.3
Apple macOS Sequoia<15.3
Apple WatchOS<11.3
Apple tvOS<18.3
Apple iPadOS<17.7.4
Apple iPadOS>=18.0<18.3
Apple iPhone OS<18.3
Apple macOS<14.7.3
Apple macOS>=15.0<15.3
Apple tvOS<18.3
Apple visionOS<2.3
Apple WatchOS<11.3
Apple tvOS<18.3
18.3
Apple macOS Sequoia<15.3
15.3
Apple macOS Sonoma<14.7.3
14.7.3
Apple visionOS<2.3
2.3
Apple iPadOS<17.7.4
17.7.4
Apple iOS<18.3
18.3
Apple iPadOS<18.3
18.3
Event History
Jan 27, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Updated
via Apple·12:00 AM
DescriptionAffected Software
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityAffected Software
Mar 31, 2025
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
Apr 1, 2025
Updated
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24163?
CVE-2025-24163 is considered a significant vulnerability due to its authentication issues and potential impact on device functionality.
2
How do I fix CVE-2025-24163?
To fix CVE-2025-24163, ensure your device is updated to the latest compatible version of Apple software.
3
What devices are affected by CVE-2025-24163?
Devices affected by CVE-2025-24163 include specific versions of iPadOS, iOS, macOS, visionOS, watchOS, and tvOS.
4
What vulnerabilities are addressed in CVE-2025-24163?
CVE-2025-24163 addresses issues such as authentication state management, null pointer dereference, type confusion, and input validation.
5
Is there a workaround for CVE-2025-24163?
No official workaround is provided for CVE-2025-24163; the recommended action is to update affected devices to secure versions.