Apple Security Advisories · January 2025 — Apple Security Advisories
84 advisories 84 CVEs 7 EXPLOITED

Apple-vendor CVEs for 2025-01. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2025-24085

visionOSExploitedCISA KEV listedCRITICAL2025-01-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious appl...

CVEs:CVE-2025-24085

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24137

visionOSExploitedCISA KEV listedHIGH2025-01-27

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3. An attacker on the local network may corrupt process memory.

CVEs:CVE-2025-24137

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24128

iPadOSExploitedCISA KEV listedMEDIUM2025-01-27

The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2025-24128

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-24159

visionOSExploitedCISA KEV listedCRITICAL2025-01-27

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to execute arbitrary code with kern...

CVEs:CVE-2025-24159

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24145

iPadOSExploitedCISA KEV listedLOW2025-01-27

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view a contact's phone number in system logs.

CVEs:CVE-2025-24145

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-24107

iPadOSExploitedCISA KEV listedCRITICAL2025-01-27

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-24107

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24113

visionOSExploitedVulnCheck KEV listedMEDIUM2025-01-27

The issue was addressed with improved UI. This issue is fixed in Safari 18.3, Safari 18.4, iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sequoia 15.4, visionOS 2.3, visionOS 2.4, watchOS 11.4. Visiting a m...

CVEs:CVE-2025-24113

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2018-4301

OtherWeaponized exploitCRITICAL2025-01-07

This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.

CVEs:CVE-2018-4301

Affected products

ProductStatusVendorPackageEcosystem
smart_card_services affected apple
Upstream advisory

CVE-2025-24118

iPadOSActive exploitation (sightings)CRITICAL2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2025-24118

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-24104

iPadOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.

CVEs:CVE-2025-24104

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24160

visionOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.

CVEs:CVE-2025-24160

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24154

visionOSActive exploitation (sightings)CRITICAL2025-01-27

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, visionOS 2.3. An attacker may be able to cause unexpected system termin...

CVEs:CVE-2025-24154

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2024-54497

visionOSActive exploitation (sightings)HIGH2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing web content may lead to a den...

CVEs:CVE-2024-54497

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24102

iPadOSActive exploitation (sightings)CRITICAL2025-01-27

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to determine a user’s current location.

CVEs:CVE-2025-24102

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-24120

macOSActive exploitation (sightings)HIGH2025-01-27

This issue was addressed by improved management of object lifetimes. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An attacker may be able to cause unexpected app termination.

CVEs:CVE-2025-24120

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24146

macOSActive exploitation (sightings)CRITICAL2025-01-27

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Deleting a conversation in Messages may expose user contact information in system logging.

CVEs:CVE-2025-24146

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24169

macOSActive exploitation (sightings)HIGH2025-01-27

A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass browser extension authentication.

CVEs:CVE-2025-24169

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-24123

visionOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected...

CVEs:CVE-2025-24123

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24103

macOSActive exploitation (sightings)CRITICAL2025-01-27

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access protected user data.

CVEs:CVE-2025-24103

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24130

macOSActive exploitation (sightings)CRITICAL2025-01-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24130

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-27856

visionOSActive exploitation (sightings)CRITICAL2025-01-15

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. Processing a file may lead to unexpected app termination...

CVEs:CVE-2024-27856

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24189

visionOSActive exploitation (sightings)CRITICAL2025-01-27

The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to memory corruption.

CVEs:CVE-2025-24189

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-54478

visionOSActive exploitation (sightings)HIGH2025-01-27

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted we...

CVEs:CVE-2024-54478

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24106

macOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-24106

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24156

macOSActive exploitation (sightings)CRITICAL2025-01-27

An integer overflow was addressed through improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to elevate privileges.

CVEs:CVE-2025-24156

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24109

macOSActive exploitation (sightings)CRITICAL2025-01-27

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access sensitive user data.

CVEs:CVE-2025-24109

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-44136

iPadOSActive exploitation (sightings)CRITICAL2025-01-15

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to a device may be able to disable Stolen Device Protection.

CVEs:CVE-2024-44136

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24140

macOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet may not have the quarantine flag applied.

CVEs:CVE-2025-24140

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24149

visionOSActive exploitation (sightings)MEDIUM2025-01-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may ...

CVEs:CVE-2025-24149

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-44142

OtherActive exploitation (sightings)CRITICAL2025-01-30

The issue was addressed with improved bounds checks. This issue is fixed in GarageBand 10.4.12. Processing a maliciously crafted image may lead to arbitrary code execution.

CVEs:CVE-2024-44142

Affected products

ProductStatusVendorPackageEcosystem
garageband affected apple
Upstream advisory

CVE-2025-24124

visionOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected...

CVEs:CVE-2025-24124

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24127

visionOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3. Parsing a file may lead to an unexpected app termination.

CVEs:CVE-2025-24127

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24161

visionOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to an unexpected app termination.

CVEs:CVE-2025-24161

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24136

macOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious app may be able to create symlinks to protected regions of the disk.

CVEs:CVE-2025-24136

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24086

visionOSActive exploitation (sightings)HIGH2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing an image may lead to...

CVEs:CVE-2025-24086

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-54470

iPadOSActive exploitation (sightings)MEDIUM2025-01-15

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1. An attacker with physical access may be able to access contacts from the lock screen.

CVEs:CVE-2024-54470

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24117

visionOSActive exploitation (sightings)HIGH2025-01-27

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, visionOS 2.3, watchOS 11.3. An app may be able to fingerprint the user.

CVEs:CVE-2025-24117

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2024-54509

macOSActive exploitation (sightings)CRITICAL2025-01-27

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2024-54509

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24115

macOSActive exploitation (sightings)MEDIUM2025-01-27

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to read files outside of its sandbox.

CVEs:CVE-2025-24115

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24174

macOSActive exploitation (sightings)HIGH2025-01-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to bypass Privacy preferences.

CVEs:CVE-2025-24174

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24134

macOSActive exploitation (sightings)HIGH2025-01-27

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24134

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24112

macOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpected app termination.

CVEs:CVE-2025-24112

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24092

macOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information.

CVEs:CVE-2025-24092

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24138

macOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious application may be able to leak sensitive user information.

CVEs:CVE-2025-24138

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24122

macOSActive exploitation (sightings)MEDIUM2025-01-27

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the fil...

CVEs:CVE-2025-24122

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24153

macOSActive exploitation (sightings)CRITICAL2025-01-27

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2025-24153

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24108

macOSActive exploitation (sightings)MEDIUM2025-01-27

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.

CVEs:CVE-2025-24108

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24100

macOSActive exploitation (sightings)LOW2025-01-27

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access information about a user's contacts.

CVEs:CVE-2025-24100

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24101

macOSActive exploitation (sightings)HIGH2025-01-27

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24101

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24096

macOSActive exploitation (sightings)MEDIUM2025-01-27

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. A malicious app may be able to access arbitrary files.

CVEs:CVE-2025-24096

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24151

macOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2025-24151

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24116

macOSActive exploitation (sightings)MEDIUM2025-01-27

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to bypass Privacy preferences.

CVEs:CVE-2025-24116

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24121

macOSActive exploitation (sightings)LOW2025-01-27

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24121

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24114

macOSActive exploitation (sightings)MEDIUM2025-01-27

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24114

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24087

macOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sequoia 15.3. An app may be able to access protected user data.

CVEs:CVE-2025-24087

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24135

macOSActive exploitation (sightings)HIGH2025-01-27

This issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated privileges.

CVEs:CVE-2025-24135

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24176

macOSActive exploitation (sightings)HIGH2025-01-27

A permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may be able to elevate their privileges.

CVEs:CVE-2025-24176

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24141

iPadOSActive exploitation (sightings)LOW2025-01-27

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.3 and iPadOS 18.3. An attacker with physical access to an unlocked device may be able to access Photos while the app is locked.

CVEs:CVE-2025-24141

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2024-54540

OtherActive exploitation (sightings)MEDIUM2025-01-15

The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.

CVEs:CVE-2024-54540

Affected products

ProductStatusVendorPackageEcosystem
music affected apple
Upstream advisory

CVE-2025-24152

macOSActive exploitation (sightings)MEDIUM2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.3. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2025-24152

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-40771

visionOSActive exploitation (sightings)CRITICAL2025-01-15

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7, tvOS 17.5, visionOS 1.2, watchOS 10.5. An app may be a...

CVEs:CVE-2024-40771

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-40839

iPadOSActive exploitation (sightings)LOW2025-01-15

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.

CVEs:CVE-2024-40839

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24094

macOSActive exploitation (sightings)HIGH2025-01-27

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24094

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24150

iPadOSPoC exploitCRITICAL2025-01-27

A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.

CVEs:CVE-2025-24150

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-24126

visionOSPoC exploitCRITICAL2025-01-27

An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able to corrupt process memory.

CVEs:CVE-2025-24126

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24129

visionOSPoC exploitHIGH2025-01-27

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause an unexpected...

CVEs:CVE-2025-24129

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24131

visionOSPoC exploitHIGH2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may be able ...

CVEs:CVE-2025-24131

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24162

visionOSPoC exploitHIGH2025-01-27

This issue was addressed through improved state management. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing maliciously crafted web content may lead to an unexpected pr...

CVEs:CVE-2025-24162

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24177

iPadOSPoC exploitHIGH2025-01-27

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker on the local network may be able to caus...

CVEs:CVE-2025-24177

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-24143

visionOSPoC exploitMEDIUM2025-01-27

The issue was addressed with improved access restrictions to the file system. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.

CVEs:CVE-2025-24143

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2025-24093

macOSPoC exploitCRITICAL2025-01-27

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access removable volumes without user consent.

CVEs:CVE-2025-24093

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-54543

visionOSPoC exploitCRITICAL2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory...

CVEs:CVE-2024-54543

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24163

visionOSPoC exploitMEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tvOS 18.3, tvOS 18.4, visionOS 2.3, visionOS 2.4, watch...

CVEs:CVE-2025-24163

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24179

visionOSPoC exploitHIGH2025-01-27

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local ne...

CVEs:CVE-2025-24179

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24139

macOSPoC exploitHIGH2025-01-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Ventura 13.7.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVEs:CVE-2025-24139

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43446

macOSPoC exploitMEDIUM2025-01-26

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-43446

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24099

macOSPoC exploitMEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local attacker may be able to elevate their privileges.

CVEs:CVE-2025-24099

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43374

visionOSPoC exploitMEDIUM2025-01-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.5, visionOS 2.5, watchOS 11.5. An attacker in phys...

CVEs:CVE-2025-43374

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24185

macOSPoC exploitCRITICAL2025-01-27

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Parsing a maliciously crafted file may lead to an unexpected app termination.

CVEs:CVE-2025-24185

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31248

macOSPoC exploitMEDIUM2025-01-27

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to access sensitive user data.

CVEs:CVE-2025-31248

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31185

iPadOSPoC exploitLOW2025-01-27

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without authentication.

CVEs:CVE-2025-31185

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24184

visionOSPoC exploitMEDIUM2025-01-27

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-24184

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31262

visionOSPoC exploitMEDIUM2025-01-27

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-31262

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24183

macOSPoC exploitMEDIUM2025-01-27

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to modify protected parts of the file system.

CVEs:CVE-2025-24183

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.