CVE-2025-24257

Published Mar 31, 2025

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-24257 is identified as an out-of-bounds write vulnerability. This issue stems from insufficient input validation, which could allow an application to perform an out-of-bounds write operation. Exploitation of this vulnerability could lead to unexpected system termination or enable an app to write directly to kernel memory. Apple has addressed this flaw in visionOS 2.4, iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4.

Description
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.
Source
product-security@apple.com
NVD status
Modified
Products
ipados, iphone_os, macos, visionos

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.1
Impact score
5.2
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-787

Social media

Hype score
Not currently trending

Configurations