← Back to browse · API

CVE-2025-24085

Severity
CRITICAL
CVSS
10.0
EPSS
0.17323
Risk score
71.06
CISA KEV
Yes
PoC
No
Published
2025-01-27
Modified
2026-04-02
First seen
2026-08-07
Aliases
EUVD-2025-3607, GHSA-7H23-57PG-3HWC
Products
Apple:Multiple Products, Apple:iOS and iPadOS 0 <18.3, Apple:iPadOS 0 <17.7.6, Apple:macOS 0 <13.7.5, Apple:macOS 0 <14.7.5, Apple:macOS 0 <15.3, Apple:tvOS 0 <18.3, Apple:visionOS 0 <2.3, Apple:watchOS 0 <11.3
Sources
euvd EUVD-2025-3607
cisa.gov CVE-2025-24085

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.

References