CVE-2025-24170: Use After Free
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.
Other sources
Accessibility. A logging issue was addressed with improved data redaction.
— Apple
AccountPolicy. This issue was addressed by removing the vulnerable code.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24234
- CVE-2025-24131
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24129
- CVE-2025-24126
- CVE-2025-24206
- CVE-2025-24276
- CVE-2024-40864
- CVE-2025-24272
- CVE-2025-24231
- CVE-2025-24233
- CVE-2025-30443
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-30460
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24085
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31191
- CVE-2025-24170
- CVE-2025-24277
- CVE-2024-9681
- CVE-2025-31189
- CVE-2025-24255
- CVE-2025-24267
- CVE-2025-30456
- CVE-2025-24111
- CVE-2025-31187
- CVE-2025-30462
- CVE-2025-24199
- CVE-2025-30447
- CVE-2025-24256
- CVE-2025-24273
- CVE-2025-30464
- CVE-2025-24210
- CVE-2025-24249
- CVE-2025-24229
- CVE-2025-24235
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-24148
- CVE-2025-24195
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-31264
- CVE-2025-24172
- CVE-2025-30450
- CVE-2025-30470
- CVE-2025-24232
- CVE-2025-24246
- CVE-2025-24261
- CVE-2025-24164
- CVE-2025-30446
- CVE-2025-24259
- CVE-2025-30424
- CVE-2025-24173
- CVE-2025-30452
- CVE-2025-24181
- CVE-2025-30471
- CVE-2025-24250
- CVE-2025-30438
- CVE-2025-31194
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24139
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-30444
- CVE-2025-24228
- CVE-2025-24260
- CVE-2025-24254
- CVE-2024-54533
- CVE-2025-24207
- CVE-2025-31261
- CVE-2025-24253
- CVE-2025-30449
- CVE-2025-31188
- CVE-2025-24240
- CVE-2025-24278
- CVE-2025-30457
- CVE-2025-24279
- CVE-2025-24247
- CVE-2025-24241
- CVE-2025-24266
- CVE-2025-24265
- CVE-2025-24157
- CVE-2025-31198
- CVE-2025-24202
- CVE-2025-24097
- CVE-2025-31202
- CVE-2025-24239
- CVE-2025-31272
- CVE-2025-30430
- CVE-2025-24180
- CVE-2025-24245
- CVE-2025-24163
- CVE-2025-31196
- CVE-2025-24236
- CVE-2025-30454
- CVE-2025-24182
- CVE-2025-31203
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30455
- CVE-2025-30451
- CVE-2025-24281
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-30461
- CVE-2025-30431
- CVE-2025-30463
- CVE-2025-30448
- CVE-2025-24257
- CVE-2025-31263
- CVE-2025-30437
- CVE-2025-24204
- CVE-2025-24196
- CVE-2024-48958
- CVE-2025-31231
- CVE-2025-24194
- CVE-2025-31199
- CVE-2025-46308
- CVE-2025-30426
- CVE-2025-24262
- CVE-2023-27043
- CVE-2025-24284
- CVE-2025-30459
- CVE-2025-24191
- CVE-2025-30466
- CVE-2025-24113
- CVE-2025-30467
- CVE-2025-31192
- CVE-2025-24167
- CVE-2025-24093
- CVE-2025-30458
- CVE-2025-24268
- CVE-2025-43184
- CVE-2025-24280
- CVE-2025-31183
- CVE-2025-30435
- CVE-2025-24217
- CVE-2025-24214
- CVE-2025-24248
- CVE-2025-24269
- CVE-2025-24165
- CVE-2025-30442
- CVE-2025-24282
- CVE-2025-24263
- CVE-2025-46293
- CVE-2025-43278
- CVE-2025-24218
- CVE-2025-24242
- CVE-2025-31195
- CVE-2025-31184
- CVE-2025-24192
- CVE-2025-24264
- CVE-2025-24216
- CVE-2025-24209
- CVE-2025-30427
- CVE-2025-30425
- CVE-2025-43465
- CVE-2025-24107
Frequently Asked Questions
What is the severity of CVE-2025-24170?
CVE-2025-24170 is considered a high severity vulnerability due to the potential for apps to gain root privileges.
How do I fix CVE-2025-24170?
To fix CVE-2025-24170, update your macOS to at least Ventura 13.7.5 or Sonoma 14.7.5.
What systems are affected by CVE-2025-24170?
CVE-2025-24170 affects macOS Ventura prior to version 13.7.5 and macOS Sonoma prior to version 14.7.5.
What type of vulnerability is CVE-2025-24170?
CVE-2025-24170 is classified as a logic issue related to file handling.
What did Apple do to address CVE-2025-24170?
Apple addressed CVE-2025-24170 by removing the vulnerable code associated with the issue.