CVE-2025-24225: Use After Free
AirDrop. A permissions issue was addressed with additional restrictions.
Other sources
An injection issue was addressed with improved input validation. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. Processing an email may lead to user interface spoofing.
— MITRE
AppleJPEG. The issue was addressed with improved input sanitization.
— Apple
Audio. A double free issue was addressed with improved memory management.
— Apple
Baseband. This issue was addressed through improved state management.
— Apple
Call History. A privacy issue was addressed by removing sensitive data.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24097
- CVE-2025-31251
- CVE-2025-31235
- CVE-2025-31208
- CVE-2025-31196
- CVE-2025-31209
- CVE-2025-31239
- CVE-2025-31233
- CVE-2025-24111
- CVE-2025-31210
- CVE-2025-30448
- CVE-2025-31226
- CVE-2025-24144
- CVE-2025-31219
- CVE-2025-31241
- CVE-2024-8176
- CVE-2025-24225
- CVE-2025-31228
- CVE-2025-24259
- CVE-2025-31245
- CVE-2025-31221
- CVE-2025-31213
- CVE-2025-31242
- CVE-2025-31220
- CVE-2025-24213
- CVE-2025-31217
- CVE-2025-31215
- CVE-2025-31206
- CVE-2025-31216
- CVE-2025-43374
- CVE-2025-31214
- CVE-2025-31225
- CVE-2025-31212
- CVE-2025-31253
- CVE-2025-31207
- CVE-2025-24224
- CVE-2025-31222
- CVE-2025-31227
- CVE-2025-31234
- CVE-2025-31223
- CVE-2025-31238
- CVE-2025-24223
- CVE-2025-31204
- CVE-2025-31205
- CVE-2025-31257
Frequently Asked Questions
What is the severity of CVE-2025-24225?
CVE-2025-24225 has been classified with a high severity level due to its potential impact on user data and device security.
How do I fix CVE-2025-24225?
To fix CVE-2025-24225, update your affected Apple devices to the latest versions, specifically iPadOS 17.7.7 or iOS/iPadOS 18.5.
What types of devices are affected by CVE-2025-24225?
CVE-2025-24225 affects Apple devices running older versions of iOS and iPadOS including models that can be upgraded to iOS 17.7.7 or 18.5.
What issues does CVE-2025-24225 address?
CVE-2025-24225 addresses multiple vulnerabilities including a permissions issue, input sanitization, memory management, and state management problems.
Is there a workaround for CVE-2025-24225?
There are no official workarounds for CVE-2025-24225; the recommended solution is to perform the advised software updates.