CVE-2025-24159

A validation issue was addressed with improved logic. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An app may be able to execute arbitrary code with kernel privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Jan/13 -
  • () http://seclists.org/fulldisclosure/2025/Jan/14 -
  • () http://seclists.org/fulldisclosure/2025/Jan/15 -
  • () http://seclists.org/fulldisclosure/2025/Jan/16 -
  • () http://seclists.org/fulldisclosure/2025/Jan/18 -
  • () http://seclists.org/fulldisclosure/2025/Jan/19 -

19 Mar 2025, 14:15

Type Values Removed Values Added
CPE cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
First Time Apple tvos
Apple iphone Os
Apple ipados
Apple watchos
Apple visionos
Apple
Apple macos
CWE CWE-94
NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://support.apple.com/en-us/122066 - () https://support.apple.com/en-us/122066 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122067 - () https://support.apple.com/en-us/122067 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122068 - () https://support.apple.com/en-us/122068 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122069 - () https://support.apple.com/en-us/122069 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122071 - () https://support.apple.com/en-us/122071 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122072 - () https://support.apple.com/en-us/122072 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122073 - () https://support.apple.com/en-us/122073 - Release Notes, Vendor Advisory

18 Feb 2025, 20:15

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : unknown

28 Jan 2025, 16:15

Type Values Removed Values Added
CWE CWE-94
Summary
  • (es) Se solucionó un problema de validación con una lógica mejorada. Este problema se solucionó en iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 y iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3 y tvOS 18.3. Es posible que una aplicación pueda ejecutar código arbitrario con privilegios de kernel.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2025-11-03 21:19


NVD link : CVE-2025-24159

Mitre link : CVE-2025-24159

CVE.ORG link : CVE-2025-24159


JSON object : View

Products Affected

apple

  • tvos
  • ipados
  • macos
  • watchos
  • iphone_os
  • visionos
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')