CRITICAL🇵🇱 Wersja polska

CVE-2025-24154

CVSS 9.1v3.1pub. 2025-01-27upd. 2026-04-02

An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, visionOS 2.3. An attacker may be able to cause unexpected system termination or corrupt kernel memory.

🤖 AI Analysis
How it works

The vulnerability is caused by an out-of-bounds write (CWE-787) due to insufficient input validation. An additional factor is the CWE-757 vulnerability, indicating the selection of a weaker or unsecured algorithm. An attacker can deliver specially crafted input data over the network without requiring privileges or user interaction, leading to writes in kernel memory areas of the system.

Impact

An attacker may cause unexpected and forced system shutdown (denial of service) or lead to kernel memory corruption, which potentially opens the door to further privilege escalation or device destabilization.

Mitigation & patch

Devices should be updated as soon as possible to the following versions: iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, or visionOS 2.3. Detailed instructions are available in Apple's official security bulletins at the addresses indicated in the references.

Who is affected

iOS and iPadOS prior to version 18.3, macOS Sequoia prior to version 15.3, macOS Sonoma prior to version 14.7.3, macOS Ventura prior to version 13.7.3, and visionOS prior to version 2.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Apple iPadOS

    OS
    Apple
    < 18.3
  • Apple iOS

    OS
    Apple
    < 18.3
  • Apple macOS

    OS
    Apple
    < 13.7.314.0 – 14.7.3 (excl.)15.0 – 15.3 (excl.)
  • Apple Visionos

    OS
    Apple
    < 2.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-31200CRITICAL9.8⚠ KEVPL ✓same product

Apple — memory corruption (RCE) w przetwarzaniu strumieni audio

CVE-2025-31201CRITICAL9.8⚠ KEVPL ✓same product

Apple: Obejście Pointer Authentication w iOS, macOS i innych platformach