CVE-2025-24085 is a critical use-after-free vulnerability affecting multiple Apple operating systems, including iOS, iPadOS, and macOS, which could lead to privilege escalation. Rated CVSS 10.0 Critical, it allows for remote, unauthenticated exploitation with low attack complexity, resulting in high impact on confidentiality, integrity, and availability. Apple has confirmed active exploitation of this flaw against iOS versions prior to 17.2, and it is listed in CISA's KEV catalog. Public exploit code exists, and the vulnerability has received significant community and media attention, with reports indicating 0-click attack vectors. Immediate patching to the latest fixed versions is strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.7.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 18.0, < 18.3CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 18.3CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.7.5CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.7.5CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.