CVE-2025-24202
Published Mar 31, 2025
·Updated
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.
Credit
Zhongcheng Li(IES Red Team of ByteDance), Lehan Dilusha@@zafer, an anonymous researcher, Ron Masas(BREAKPOINT), Uri Katz (Oligo Security), Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Dominik Rath, Martin Kreichgauer(Google Chrome), Yutong Xiu@@Sou1gh0st, Denis Tokarev@@illusionofcha0s, Google Threat Analysis Group, wac(Trend Micro Zero Day Initiative), pattern-f@@pattern_F_, Jonathan Bar Or@@yo_yo_yo_jbo(Microsoft), CVE-2024-9681, Gergely Kalman@@gergely_kalman, Andr.Ess, Kirin@@Pwnrin, LFY@@secsys(Fudan University), mzzzz__, Anonymous(Trend Micro Zero Day Initiative), Wang Yu(Cyberserval), Muhammad Zaid Ghifari (Mr.ZheeV), Kalimantan Utara, Michael (Biscuit) Thomas - @social.lol@@biscuit, CVE-2024-48958, CVE-2025-27113, CVE-2024-56171, Alex Radocea(Supernetworks), Dave G.(Supernetworks), 风沐云烟@@binary_fmyy, Minghao Lin@@Y1nKoc, Alexia Wilson(Microsoft), Christine Fossaceca(Microsoft), Florian Draschbacher, Jimmy, Jax Reissner, Dalibor Milanovic, Mickey Jin@@patch1t, Jaydev Ahire, @@RenwaX23, Syarif Muhammad Sajjad, Wojciech Regula(SecuRing), Bing Shi(Alibaba Group), Wenchao Li(Alibaba Group), Xiaolong Bai(Alibaba Group), Luyi Xing(Indiana University Bloomington), Halle Winkler, Politepix theoffcuts.org, Andrew James Gonzalez, Abhay Kailasia@@abhay_kailasia(C), Chi Yuan Chang(ZUSO ART), taikosoup, Bohdan Stasiuk@@bohdan_stasiuk, YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), Richard Hyunho Im with routezero.security@@richeeta, Alexander Heinrich@@Sn0wfreeze, SEEMOO, TU Darmstadt & Mathy Vanhoef@@vanhoefm, Jeroen Robben@@RobbenJeroen, DistriNet, KU Leuven, Vsevolod Kokorin (Slonser)(Solidlab), Gary Kwong, Paul Bakker(ParagonERP), Francisco Alonso@@revskills, rheza@@ginggilBesel, Claudio Bozzato(Cisco Talos), Francesco Benvenuto(Cisco Talos), Ian Mckay@@iann0036, Csaba Fitzl@@theevilbit(Kandji), Nolan Astrein(Kandji), Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Pietro Francesco Tirenna(Shielder), Davide Silvetti(Shielder), Abdel Adim Oisfi(Shielder), luckyu@@uuulucky, Rodolphe BRUNETTI@@eisw0lf, Manuel Fernandez (Stackhopper Security), ABC Research s.r.o., Murray Mike, Dayton Pidhirney(Atredis Partners), Lyutoon, YenKoc, Ye Zhang@@VAR10CK(Baidu Security), Koh M. Nakagawa@@tsunek0h(FFRI Security Inc), Ian Beer(Google Project Zero), Joseph Ravichandran@@0xjprx(MIT CSAIL), Kenneth Chew, Paweł Płatek (Trail(Bits), Diamant Osmani & Valdrin Haliti [Kosovë], dbpeppe, Solitechworld, Pwn2car, Mickey Jin@@patch1t(Kandji), (Kandji), Pedro Tôrres@@t0rr3sp3dr0, Noah Gregory (wts.dev), CVE-2023-27043, Yiğit Can YILMAZ@@yilmazcanyigit, Arsenii Kostromin (0x3c3e), Dolf Hoegaerts, Michiel Devliegere, K宝@@Pwnrin, Tong Liu@@Lyutoon_, 风(binary_fmyy), F00L, zbleet(QI), Cristian Dinca(Computer Science), Romania, 风沐云烟 (binary_fmyy), Kirin, FlowerCode, Zhongquan Li@@Guluisacat, Pedro José Pereira Vieito / pvieito.com)@@pvieito, PixiePoint Security, Andreas Hegenberg (folivora.AI GmbH)
Affected Software
6 affected componentsFixes available
Apple iOS, iPadOS, and macOS<18.4
iPhone OS<18.4
macOS>=15.0<15.4
Apple iOS and iPadOS<18.4
18.4
Apple iOS, iPadOS, and macOS<18.4
18.4
macOS<15.4
15.4
Event History
Mar 31, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
Affected Software
CVE Published
via MITRE·10:24 PM
Data Sourced
via MITRE·10:24 PM
DescriptionWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24202?
CVE-2025-24202 is classified as a medium severity logging issue that could allow an app to access sensitive user data.
2
How do I fix CVE-2025-24202?
To fix CVE-2025-24202, update your Apple iOS or iPadOS to version 18.4 or macOS Sequoia to version 15.4.
3
What products are affected by CVE-2025-24202?
CVE-2025-24202 affects Apple iOS, iPadOS, and macOS versions prior to 18.4 and 15.4 respectively.
4
What type of issue is CVE-2025-24202?
CVE-2025-24202 pertains to a logging issue that involves insufficient data redaction.
5
Is CVE-2025-24202 still a risk if I have updated my software?
No, updating to the patched versions of Apple iOS, iPadOS, and macOS resolves the risk associated with CVE-2025-24202.