CVE-2025-24249: Use After Free
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to check the existence of an arbitrary path on the file system.
Other sources
Accessibility. A logging issue was addressed with improved data redaction.
— Apple
AccountPolicy. This issue was addressed by removing the vulnerable code.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24234
- CVE-2025-24131
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24129
- CVE-2025-24126
- CVE-2025-24206
- CVE-2025-24276
- CVE-2024-40864
- CVE-2025-24272
- CVE-2025-24231
- CVE-2025-24233
- CVE-2025-30443
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-30460
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24085
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31191
- CVE-2025-24170
- CVE-2025-24277
- CVE-2024-9681
- CVE-2025-31189
- CVE-2025-24255
- CVE-2025-24267
- CVE-2025-30456
- CVE-2025-24111
- CVE-2025-31187
- CVE-2025-30462
- CVE-2025-24199
- CVE-2025-30447
- CVE-2025-24256
- CVE-2025-24273
- CVE-2025-30464
- CVE-2025-24210
- CVE-2025-24249
- CVE-2025-24229
- CVE-2025-24235
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-24148
- CVE-2025-24195
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-31264
- CVE-2025-24172
- CVE-2025-30450
- CVE-2025-30470
- CVE-2025-24232
- CVE-2025-24246
- CVE-2025-24261
- CVE-2025-24164
- CVE-2025-30446
- CVE-2025-24259
- CVE-2025-30424
- CVE-2025-24173
- CVE-2025-30452
- CVE-2025-24181
- CVE-2025-30471
- CVE-2025-24250
- CVE-2025-30438
- CVE-2025-31194
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24139
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-30444
- CVE-2025-24228
- CVE-2025-24260
- CVE-2025-24254
- CVE-2024-54533
- CVE-2025-24207
- CVE-2025-31261
- CVE-2025-24253
- CVE-2025-30449
- CVE-2025-31188
- CVE-2025-24240
- CVE-2025-24278
- CVE-2025-30457
- CVE-2025-24279
- CVE-2025-24247
- CVE-2025-24241
- CVE-2025-24266
- CVE-2025-24265
- CVE-2025-24157
- CVE-2025-31198
- CVE-2025-24202
- CVE-2025-24097
- CVE-2025-31202
- CVE-2025-24239
- CVE-2025-31272
- CVE-2025-30430
- CVE-2025-24180
- CVE-2025-24245
- CVE-2025-24163
- CVE-2025-31196
- CVE-2025-24236
- CVE-2025-30454
- CVE-2025-24182
- CVE-2025-31203
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30455
- CVE-2025-30451
- CVE-2025-24281
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-30461
- CVE-2025-30431
- CVE-2025-30463
- CVE-2025-30448
- CVE-2025-24257
- CVE-2025-31263
- CVE-2025-30437
- CVE-2025-24204
- CVE-2025-24196
- CVE-2024-48958
- CVE-2025-31231
- CVE-2025-24194
- CVE-2025-31199
- CVE-2025-46308
- CVE-2025-30426
- CVE-2025-24262
- CVE-2023-27043
- CVE-2025-24284
- CVE-2025-30459
- CVE-2025-24191
- CVE-2025-30466
- CVE-2025-24113
- CVE-2025-30467
- CVE-2025-31192
- CVE-2025-24167
- CVE-2025-24093
- CVE-2025-30458
- CVE-2025-24268
- CVE-2025-43184
- CVE-2025-24280
- CVE-2025-31183
- CVE-2025-30435
- CVE-2025-24217
- CVE-2025-24214
- CVE-2025-24248
- CVE-2025-24269
- CVE-2025-24165
- CVE-2025-30442
- CVE-2025-24282
- CVE-2025-24263
- CVE-2025-46293
- CVE-2025-43278
- CVE-2025-24218
- CVE-2025-24242
- CVE-2025-31195
- CVE-2025-31184
- CVE-2025-24192
- CVE-2025-24264
- CVE-2025-24216
- CVE-2025-24209
- CVE-2025-30427
- CVE-2025-30425
- CVE-2025-43465
- CVE-2025-24107
Frequently Asked Questions
What is the severity of CVE-2025-24249?
CVE-2025-24249 is classified as a medium severity vulnerability due to its potential to allow apps to access arbitrary paths on the file system.
How do I fix CVE-2025-24249?
To fix CVE-2025-24249, update your macOS to at least Ventura 13.7.5, Sequoia 15.4, or Sonoma 14.7.5.
What product versions are affected by CVE-2025-24249?
CVE-2025-24249 affects macOS versions from 13.0 to 13.7.4, 14.0 to 14.7.4, and 15.0 to 15.3.
What type of issue does CVE-2025-24249 address?
CVE-2025-24249 addresses a permissions issue that was mitigated by implementing additional sandbox restrictions.
Can I check if my system is vulnerable to CVE-2025-24249?
You can check if your system is vulnerable to CVE-2025-24249 by verifying if it is running a version of macOS prior to the fixed versions of Ventura 13.7.5, Sequoia 15.4, or Sonoma 14.7.5.