The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted font may result in the disclosure of process memory.
                
            References
                    Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    03 Nov 2025, 22:18
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
        
        
  | 
03 Nov 2025, 20:17
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*  | 
|
| References | 
        
        
  | 
|
| References | () https://support.apple.com/en-us/122371 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/122372 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/122373 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/122374 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/122375 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/122377 - Vendor Advisory | |
| First Time | 
        
        Apple
         Apple macos Apple iphone Os Apple ipados Apple tvos  | 
02 Apr 2025, 16:17
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-200 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 5.5  | 
| Summary | 
        
        
  | 
31 Mar 2025, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-31 23:15
Updated : 2025-11-03 22:18
NVD link : CVE-2025-24244
Mitre link : CVE-2025-24244
CVE.ORG link : CVE-2025-24244
JSON object : View
Products Affected
                apple
- tvos
 - ipados
 - macos
 - iphone_os
 
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
