CVE-2025-24223: Double Free
afpfs. The issue was addressed with improved memory handling.
Other sources
afpfs. This issue was addressed with improved checks.
— Apple
Apple Intelligence Reports. A permissions issue was addressed with additional restrictions.
— Apple
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Audio. A double free issue was addressed with improved memory management.
— Apple
Baseband. This issue was addressed through improved state management.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.5 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.5 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.5 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 11.5 - Configuration
Ensure the affected file quarantine behavior includes the additional checks that address the quarantine bypass (applies to the component noted as 'quarantine').
quarantine file_quarantine = additional checks - Configuration
Update the affected logging behavior to use improved data redaction to address the logging issue.
WebKit logging data handling = improved data redaction - Configuration
Apply the privacy fixes by removing sensitive data and improving private data redaction for log entries (as described: 'removing sensitive data', 'removing the vulnerable code', 'improved private data redaction for log entries').
WebKit private data handling = remove sensitive data / improved private data redaction for log entries - Configuration
Apply the spoofing fix by using improved truncation when displaying the fully qualified domain name.
WebKit FQDN display truncation = improved truncation - Configuration
Apply the changes described for the affected OpenSSH component: improved input validation and, where stated, removal of the vulnerable code to address injection/input-validation issues.
OpenSSH input validation = improved input validation / removing vulnerable code - Compensating control
Process maliciously crafted web content may lead to memory corruption; mitigate exposure by restricting or filtering access to untrusted/maliciously crafted web content until patched.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-31251
- CVE-2025-31212
- CVE-2025-31200
- CVE-2025-31208
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-31226
- CVE-2025-24224
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-31222
- CVE-2025-31221
- CVE-2025-31242
- CVE-2025-24213
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31205
- CVE-2025-31257
- CVE-2025-43374
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31253
- CVE-2025-31210
- CVE-2025-31207
- CVE-2025-30448
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-31227
- CVE-2025-31245
- CVE-2025-31234
- CVE-2025-31216
- CVE-2025-31266
- CVE-2025-31246
- CVE-2025-31240
- CVE-2025-31237
- CVE-2025-31260
- CVE-2025-31235
- CVE-2025-24222
- CVE-2025-31236
- CVE-2025-30443
- CVE-2025-31232
- CVE-2025-30440
- CVE-2025-24274
- CVE-2025-31218
- CVE-2025-31256
- CVE-2025-24142
- CVE-2025-26465
- CVE-2025-26466
- CVE-2025-31244
- CVE-2025-31258
- CVE-2025-31249
- CVE-2025-31224
- CVE-2025-31213
- CVE-2025-31247
- CVE-2025-31259
- CVE-2025-31250
- CVE-2025-31248
- CVE-2025-31220
Frequently Asked Questions
What is the severity of CVE-2025-24223?
CVE-2025-24223 has been classified with a severity level indicating it poses significant risks to affected Apple products.
How do I fix CVE-2025-24223?
To fix CVE-2025-24223, update your affected Apple device to the latest version available that addresses the vulnerability.
Which products are affected by CVE-2025-24223?
CVE-2025-24223 affects tvOS, macOS Sequoia, visionOS, iOS, iPadOS, and watchOS versions prior to specified updates.
What type of vulnerability is CVE-2025-24223?
CVE-2025-24223 involves issues related to memory handling and input sanitization, leading to potential permissions escalation.
Has CVE-2025-24223 been addressed in recent updates?
Yes, CVE-2025-24223 has been addressed with improved memory handling and additional restrictions in recent updates.