Apple Security Advisories · March 2025 — Apple Security Advisories
167 advisories 167 CVEs 1 EXPLOITED

Apple-vendor CVEs for 2025-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2025-24201

iPadOSExploitedCISA KEV listedCRITICAL2025-03-10

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequ...

CVEs:CVE-2025-24201

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-30436

iPadOSActive exploitation (sightings)CRITICAL2025-03-31

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker may be able to use Siri to enable Auto-Answer Calls.

CVEs:CVE-2025-30436

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-31203

visionOSActive exploitation (sightings)CRITICAL2025-03-31

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may be ab...

CVEs:CVE-2025-31203

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31263

macOSActive exploitation (sightings)CRITICAL2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.

CVEs:CVE-2025-31263

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30466

visionOSActive exploitation (sightings)CRITICAL2025-03-31

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. A website may be able to bypass Same Origin Policy.

CVEs:CVE-2025-30466

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2022-43454

iPadOSActive exploitation (sightings)CRITICAL2025-03-10

A double free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2022-43454

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31198

macOSActive exploitation (sightings)MEDIUM2025-03-31

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A path handling issue was addressed with improved validation.

CVEs:CVE-2025-31198

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2022-48610

iPadOSActive exploitation (sightings)HIGH2025-03-10

This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2. An app may be able to access user-sensitive data.

CVEs:CVE-2022-48610

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2025-31202

visionOSActive exploitation (sightings)HIGH2025-03-31

A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to cause a denial-of-service.

CVEs:CVE-2025-31202

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31189

macOSActive exploitation (sightings)HIGH2025-03-31

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.

CVEs:CVE-2025-31189

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31231

macOSActive exploitation (sightings)MEDIUM2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read sensitive location information.

CVEs:CVE-2025-31231

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2023-28207

macOSActive exploitation (sightings)MEDIUM2025-03-21

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.

CVEs:CVE-2023-28207

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-43205

visionOSActive exploitation (sightings)MEDIUM2025-03-31

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may ...

CVEs:CVE-2025-43205

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-24252

visionOSCoalition ESS > 63%CRITICAL2025-03-31

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local netwo...

CVEs:CVE-2025-24252

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31199

visionOSCoalition ESS > 63%MEDIUM2025-03-31

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2, visionOS 2.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-31199

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24190

visionOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafte...

CVEs:CVE-2025-24190

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24211

visionOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file ...

CVEs:CVE-2025-24211

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24230

visionOSPoC exploitCRITICAL2025-03-31

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Playing a ma...

CVEs:CVE-2025-24230

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24237

visionOSPoC exploitCRITICAL2025-03-31

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpe...

CVEs:CVE-2025-24237

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24178

iPadOSPoC exploitCRITICAL2025-03-31

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to break out of its s...

CVEs:CVE-2025-24178

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-30471

visionOSPoC exploitHIGH2025-03-31

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A remote user may be able to cau...

CVEs:CVE-2025-30471

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24204

macOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVEs:CVE-2025-24204

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30433

visionOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. A shortcut may be able to access file...

CVEs:CVE-2025-30433

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31182

visionOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to delete files for w...

CVEs:CVE-2025-31182

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30457

macOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to create symlinks to protected regions of the disk.

CVEs:CVE-2025-30457

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30426

visionOSPoC exploitCRITICAL2025-03-31

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to enumerate a user's installed apps.

CVEs:CVE-2025-30426

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31183

iPadOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-31183

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-24256

macOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to disclose kernel memory.

CVEs:CVE-2025-24256

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30430

visionOSPoC exploitCRITICAL2025-03-31

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. Password autofill may fill in passwords after failing authentication.

CVEs:CVE-2025-30430

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24231

macOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24231

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24238

iPadOSPoC exploitCRITICAL2025-03-31

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to gain elevated privileges.

CVEs:CVE-2025-24238

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-24232

macOSPoC exploitCRITICAL2025-03-31

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access arbitrary files.

CVEs:CVE-2025-24232

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30452

macOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An input validation issue was addressed.

CVEs:CVE-2025-30452

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30465

iPadOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with improved validation. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sequoia 15.7.2, macOS Sonoma 14.7.5, macOS Sonoma 14.8.2, macOS Tahoe 26.1, macOS Ventura 13.7.5. A shortcut may be able to acce...

CVEs:CVE-2025-30465

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-24266

macOSPoC exploitCRITICAL2025-03-31

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-24266

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24207

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to enable iCloud storage features without user consent.

CVEs:CVE-2025-24207

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24241

macOSPoC exploitCRITICAL2025-03-31

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to trick a user into copying sensitive data to the pasteboard.

CVEs:CVE-2025-24241

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24181

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

CVEs:CVE-2025-24181

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24233

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to read or write to protected files.

CVEs:CVE-2025-24233

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24180

visionOSPoC exploitHIGH2025-03-31

The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. A malicious website may be able to claim WebAuthn credentials from another website tha...

CVEs:CVE-2025-24180

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2025-31194

macOSPoC exploitCRITICAL2025-03-31

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A Shortcut may run with admin privileges without authentication.

CVEs:CVE-2025-31194

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30424

macOSPoC exploitCRITICAL2025-03-31

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Deleting a conversation in Messages may expose user contact information in system logging.

CVEs:CVE-2025-30424

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24247

macOSPoC exploitCRITICAL2025-03-31

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker may be able to cause unexpected app termination.

CVEs:CVE-2025-24247

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24253

macOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

CVEs:CVE-2025-24253

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24265

macOSPoC exploitCRITICAL2025-03-31

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-24265

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24246

macOSPoC exploitCRITICAL2025-03-31

An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24246

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24250

macOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.

CVEs:CVE-2025-24250

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24273

macOSPoC exploitCRITICAL2025-03-31

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2025-24273

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24172

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. "Block All Remote Content" may not apply for all mail previews.

CVEs:CVE-2025-24172

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24195

macOSPoC exploitCRITICAL2025-03-31

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.

CVEs:CVE-2025-24195

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24167

iPadOSPoC exploitCRITICAL2025-03-31

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. A download's origin may be incorrectly associated.

CVEs:CVE-2025-24167

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2025-24196

macOSPoC exploitHIGH2025-03-31

A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.

CVEs:CVE-2025-24196

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30446

macOSPoC exploitMEDIUM2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app with root privileges may be able to modify the contents of system files.

CVEs:CVE-2025-30446

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24260

macOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker in a privileged position may be able to perform a denial-of-service.

CVEs:CVE-2025-24260

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24209

iPadOSPoC exploitCRITICAL2025-03-31

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an une...

CVEs:CVE-2025-24209

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2025-24249

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to check the existence of an arbitrary path on the file system.

CVEs:CVE-2025-24249

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30462

macOSPoC exploitCRITICAL2025-03-31

A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.

CVEs:CVE-2025-30462

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24221

visionOSPoC exploitHIGH2025-03-31

This issue was addressed with improved data access restriction. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, visionOS 2.4. Sensitive keychain data may be accessible from an iOS backup.

CVEs:CVE-2025-24221

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
Upstream advisory

CVE-2025-30432

visionOSPoC exploitMEDIUM2025-03-31

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to attempt passcod...

CVEs:CVE-2025-30432

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30427

visionOSPoC exploitCRITICAL2025-03-31

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may...

CVEs:CVE-2025-30427

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24254

macOSPoC exploitHIGH2025-03-31

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.

CVEs:CVE-2025-24254

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30425

iPadOSPoC exploitMEDIUM2025-03-31

This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. A malicious website may be able to track users in Safari private brows...

CVEs:CVE-2025-30425

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2025-24216

visionOSPoC exploitHIGH2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an une...

CVEs:CVE-2025-24216

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24229

macOSPoC exploitHIGH2025-03-31

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A sandboxed app may be able to access sensitive user data.

CVEs:CVE-2025-24229

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24192

visionOSPoC exploitHIGH2025-03-31

A script imports issue was addressed with improved isolation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. Visiting a website may leak sensitive data.

CVEs:CVE-2025-24192

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2025-30444

macOSPoC exploitCRITICAL2025-03-31

A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Mounting a maliciously crafted SMB network share may lead to system termination.

CVEs:CVE-2025-30444

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24259

iPadOSPoC exploitCRITICAL2025-03-31

This issue was addressed with additional entitlement checks. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to retrieve Safari bookmarks without an entitlement check.

CVEs:CVE-2025-24259

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24269

macOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-24269

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30460

macOSPoC exploitHIGH2025-03-31

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

CVEs:CVE-2025-30460

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30458

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read files outside of its sandbox.

CVEs:CVE-2025-30458

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24194

visionOSPoC exploitMEDIUM2025-03-31

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.

CVEs:CVE-2025-24194

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2024-54533

macOSPoC exploitHIGH2025-03-31

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.

CVEs:CVE-2024-54533

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24157

macOSPoC exploitCRITICAL2025-03-31

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2025-24157

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24203

visionOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to modify protected p...

CVEs:CVE-2025-24203

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
macos affected apple
Upstream advisory

CVE-2025-30461

macOSPoC exploitCRITICAL2025-03-31

An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVEs:CVE-2025-30461

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24095

visionOSPoC exploitHIGH2025-03-31

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, visionOS 2.4. An app may be able to bypass Privacy preferences.

CVEs:CVE-2025-24095

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
visionos affected apple
Upstream advisory

CVE-2025-24245

macOSPoC exploitCRITICAL2025-03-31

This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.

CVEs:CVE-2025-24245

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24272

macOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24272

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2024-40864

iPadOSPoC exploitLOW2025-03-31

The issue was addressed with improved handling of protocols. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.2, watchOS 11.2. An attacker in a privileged network position may be ab...

CVEs:CVE-2024-40864

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31192

iPadOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.

CVEs:CVE-2025-31192

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-24208

iPadOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.

CVEs:CVE-2025-24208

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
safari affected apple
Upstream advisory

CVE-2025-24239

macOSPoC exploitMEDIUM2025-03-31

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVEs:CVE-2025-24239

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24279

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access contacts.

CVEs:CVE-2025-24279

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24243

visionOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafte...

CVEs:CVE-2025-24243

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30467

iPadOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, watchOS 11.4. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2025-30467

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
Upstream advisory

CVE-2025-30437

macOSPoC exploitHIGH2025-03-31

The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.

CVEs:CVE-2025-30437

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24271

visionOSPoC exploitMEDIUM2025-03-31

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An unauthenticated user on the same...

CVEs:CVE-2025-24271

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24263

macOSPoC exploitCRITICAL2025-03-31

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15.4. An app may be able to observe unprotected user data.

CVEs:CVE-2025-24263

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24193

iPadOSPoC exploitLOW2025-03-31

This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.

CVEs:CVE-2025-24193

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24235

macOSPoC exploitMEDIUM2025-03-31

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A remote attacker may be able to cause unexpected app termination or heap corruption.

CVEs:CVE-2025-24235

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31191

iPadOSPoC exploitMEDIUM2025-03-31

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-31191

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-24198

iPadOSPoC exploitMEDIUM2025-03-31

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to u...

CVEs:CVE-2025-24198

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-24213

visionOSPoC exploitCRITICAL2025-03-31

This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.

CVEs:CVE-2025-24213

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2025-24248

macOSPoC exploitMEDIUM2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.

CVEs:CVE-2025-24248

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30439

visionOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.

CVEs:CVE-2025-30439

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24251

visionOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An attacker on the local network may cau...

CVEs:CVE-2025-24251

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-30445

visionOSPoC exploitMEDIUM2025-03-31

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may caus...

CVEs:CVE-2025-30445

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30456

iPadOSPoC exploitCRITICAL2025-03-31

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVEs:CVE-2025-30456

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-24097

iPadOSPoC exploitHIGH2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.

CVEs:CVE-2025-24097

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-24206

visionOSPoC exploitCRITICAL2025-03-31

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local netwo...

CVEs:CVE-2025-24206

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30428

iPadOSPoC exploitMEDIUM2025-03-31

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6. Photos in the Hidden Photos Album may be viewed without authentication.

CVEs:CVE-2025-30428

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24228

macOSPoC exploitCRITICAL2025-03-31

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2025-24228

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24270

visionOSPoC exploitMEDIUM2025-03-31

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be ab...

CVEs:CVE-2025-24270

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30470

visionOSPoC exploitMEDIUM2025-03-31

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to read sensitive location information.

CVEs:CVE-2025-30470

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24173

visionOSPoC exploitHIGH2025-03-31

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to bre...

CVEs:CVE-2025-24173

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24210

visionOSPoC exploitMEDIUM2025-03-31

A logic error was addressed with improved error handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Parsing an image may lead to...

CVEs:CVE-2025-24210

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24244

iPadOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. Processing a maliciously crafted font may res...

CVEs:CVE-2025-24244

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-30447

visionOSPoC exploitMEDIUM2025-03-31

The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive u...

CVEs:CVE-2025-30447

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24212

visionOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its ...

CVEs:CVE-2025-24212

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-31197

visionOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may cause an unexpect...

CVEs:CVE-2025-31197

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30429

visionOSPoC exploitMEDIUM2025-03-31

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to br...

CVEs:CVE-2025-30429

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30454

iPadOSPoC exploitMEDIUM2025-03-31

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. A malicious app may be able to access private information.

CVEs:CVE-2025-30454

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-24182

visionOSPoC exploitMEDIUM2025-03-31

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of ...

CVEs:CVE-2025-24182

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24242

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app with root privileges may be able to access private information.

CVEs:CVE-2025-24242

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24164

macOSPoC exploitMEDIUM2025-03-31

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24164

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30438

visionOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to dismiss th...

CVEs:CVE-2025-30438

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
watchos affected apple
Upstream advisory

CVE-2025-30464

macOSPoC exploitCRITICAL2025-03-31

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2025-30464

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24191

macOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved validation of environment variables. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24191

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24205

iPadOSPoC exploitHIGH2025-03-31

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24205

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-24214

visionOSPoC exploitMEDIUM2025-03-31

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-24214

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24278

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

CVEs:CVE-2025-24278

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24217

iPadOSPoC exploitHIGH2025-03-31

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-24217

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
Upstream advisory

CVE-2025-24234

macOSPoC exploitCRITICAL2025-03-31

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to gain root privileges.

CVEs:CVE-2025-24234

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24255

macOSPoC exploitHIGH2025-03-31

A file access issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to break out of its sandbox.

CVEs:CVE-2025-24255

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30443

macOSPoC exploitHIGH2025-03-31

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sequoia 15.5, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

CVEs:CVE-2025-30443

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24283

visionOSPoC exploitMEDIUM2025-03-31

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-24283

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-24236

macOSPoC exploitMEDIUM2025-03-31

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-24236

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24199

macOSPoC exploitHIGH2025-03-31

An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause a denial-of-service.

CVEs:CVE-2025-24199

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30463

iPadOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-30463

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-30469

iPadOSPoC exploitLOW2025-03-31

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4. A person with physical access to an iOS device may be able to access photos from the lock screen.

CVEs:CVE-2025-30469

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24257

visionOSPoC exploitCRITICAL2025-03-31

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.

CVEs:CVE-2025-24257

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
visionos affected apple
Upstream advisory

CVE-2025-30434

iPadOSPoC exploitCRITICAL2025-03-31

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.

CVEs:CVE-2025-30434

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2025-24281

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-24281

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30450

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.

CVEs:CVE-2025-30450

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24170

macOSPoC exploitCRITICAL2025-03-31

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVEs:CVE-2025-24170

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24202

iPadOSPoC exploitMEDIUM2025-03-31

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-24202

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-24215

iPadOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVEs:CVE-2025-24215

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
macos affected apple
Upstream advisory

CVE-2025-24282

macOSPoC exploitMEDIUM2025-03-31

A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24282

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30435

macOSPoC exploitHIGH2025-03-31

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.

CVEs:CVE-2025-30435

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31184

visionOSPoC exploitHIGH2025-03-31

This issue was addressed with improved permissions checking. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4. An app may gain unauthorized access to Local Network.

CVEs:CVE-2025-31184

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
safari affected apple
visionos affected apple
Upstream advisory

CVE-2025-24262

macOSPoC exploitMEDIUM2025-03-31

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.

CVEs:CVE-2025-24262

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31187

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-31187

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24280

macOSPoC exploitHIGH2025-03-31

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24280

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30455

macOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.

CVEs:CVE-2025-30455

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24277

macOSPoC exploitCRITICAL2025-03-31

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVEs:CVE-2025-24277

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30449

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVEs:CVE-2025-30449

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24261

macOSPoC exploitMEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVEs:CVE-2025-24261

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24276

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVEs:CVE-2025-24276

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24218

macOSPoC exploitMEDIUM2025-03-31

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.4. An app may be able to access information about a user's contacts.

CVEs:CVE-2025-24218

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31264

macOSPoC exploitMEDIUM2025-03-31

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access to a locked device may be able to view sensitive user information.

CVEs:CVE-2025-31264

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-46308

iPadOSPoC exploitMEDIUM2025-03-31

An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.

CVEs:CVE-2025-46308

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
Upstream advisory

CVE-2025-30451

macOSPoC exploitHIGH2025-03-31

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-30451

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24267

macOSPoC exploitCRITICAL2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

CVEs:CVE-2025-24267

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31188

macOSPoC exploitHIGH2025-03-31

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to bypass Privacy preferences.

CVEs:CVE-2025-31188

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24240

macOSPoC exploitHIGH2025-03-31

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

CVEs:CVE-2025-24240

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24148

macOSPoC exploitMEDIUM2025-03-31

This issue was addressed with improved handling of executable types. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious JAR file may bypass Gatekeeper checks.

CVEs:CVE-2025-24148

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31195

macOSPoC exploitMEDIUM2025-03-31

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

CVEs:CVE-2025-31195

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31261

macOSPoC exploitMEDIUM2025-03-31

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

CVEs:CVE-2025-31261

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24226

XcodeCoalition ESS < 30%MEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.

CVEs:CVE-2025-24226

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2025-30441

XcodeCoalition ESS < 30%HIGH2025-03-31

This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.

CVEs:CVE-2025-30441

Affected products

ProductStatusVendorPackageEcosystem
xcode affected apple
Upstream advisory

CVE-2025-43278

macOSCoalition ESS < 30%MEDIUM2025-03-31

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVEs:CVE-2025-43278

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24268

macOSCoalition ESS < 30%MEDIUM2025-03-31

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.

CVEs:CVE-2025-24268

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-46293

macOSCoalition ESS < 30%MEDIUM2025-03-31

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

CVEs:CVE-2025-46293

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24284

macOSCoalition ESS < 30%HIGH2025-03-31

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.

CVEs:CVE-2025-24284

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-30431

macOSCoalition ESS < 30%MEDIUM2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVEs:CVE-2025-30431

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-24165

macOSCoalition ESS < 30%MEDIUM2025-03-31

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

CVEs:CVE-2025-24165

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2025-31272

macOSCoalition ESS < 30%HIGH2025-03-31

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.

CVEs:CVE-2025-31272

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.