CVE-2025-24154
27.01.2025, 22:15
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.3, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An attacker may be able to cause unexpected system termination or corrupt kernel memory.
Vendor | Product | Version |
---|---|---|
apple | ipados | 𝑥 < 18.3 |
apple | iphone_os | 𝑥 < 18.3 |
apple | macos | 𝑥 < 13.7.3 |
apple | macos | 14.0 ≤ 𝑥 < 14.7.3 |
apple | macos | 15.0 ≤ 𝑥 < 15.3 |
apple | visionos | 𝑥 < 2.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.
- CWE-757 - Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties.
Vulnerability Media Exposure