CVE-2025-24085
KEVCRITICAL 10.0EPSS 17.6%
A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 17.65% chance of exploitation in the next 30 days, 97th percentile
- CISA KEV
- added 2025-01-29
- Published
- 2025-01-27
- Updated
- 2026-04-02
Proof-of-concept exploits (2)
- 5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-242015★ · 2025-08-30
- b1n4r1b01/n-days530★ · 2025-09-28