A type confusion issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected application termination or arbitrary code execution.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/122066 | Vendor Advisory Release Notes |
https://support.apple.com/en-us/122067 | Vendor Advisory Release Notes |
https://support.apple.com/en-us/122068 | Vendor Advisory Release Notes |
https://support.apple.com/en-us/122069 | Vendor Advisory Release Notes |
https://support.apple.com/en-us/122071 | Vendor Advisory Release Notes |
https://support.apple.com/en-us/122072 | Vendor Advisory Release Notes |
https://support.apple.com/en-us/122073 | Vendor Advisory Release Notes |
Configurations
Configuration 1 (hide)
|
History
24 Mar 2025, 15:02
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
|
References | () https://support.apple.com/en-us/122066 - Vendor Advisory, Release Notes | |
References | () https://support.apple.com/en-us/122067 - Vendor Advisory, Release Notes | |
References | () https://support.apple.com/en-us/122068 - Vendor Advisory, Release Notes | |
References | () https://support.apple.com/en-us/122069 - Vendor Advisory, Release Notes | |
References | () https://support.apple.com/en-us/122071 - Vendor Advisory, Release Notes | |
References | () https://support.apple.com/en-us/122072 - Vendor Advisory, Release Notes | |
References | () https://support.apple.com/en-us/122073 - Vendor Advisory, Release Notes | |
First Time |
Apple tvos
Apple iphone Os Apple ipados Apple watchos Apple visionos Apple Apple macos |
28 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.0 |
Summary |
|
|
CWE | CWE-843 |
27 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-27 22:15
Updated : 2025-03-24 15:02
NVD link : CVE-2025-24137
Mitre link : CVE-2025-24137
CVE.ORG link : CVE-2025-24137
JSON object : View
Products Affected
apple
- visionos
- iphone_os
- watchos
- tvos
- macos
- ipados
CWE
CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')