CVE-2025-24085
About
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
Rainforest analyst review
This is a use-after-free bug in Apple's operating systems, addressed with improved memory management across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. A use-after-free occurs when code keeps using memory that has already been freed, and here a malicious application on the device can manipulate that dangling state to corrupt memory and elevate its privileges beyond the sandbox it should be confined to. The path runs through a local app rather than a remote request, so it is a privilege-escalation primitive an attacker chains after gaining some initial foothold.
Apple has acknowledged reports that this was actively exploited against versions before iOS 17.2, which is the signature of targeted mobile intrusion work, where a lower-privilege bug or malicious app is combined with a kernel or system escalation like this to take full control of a phone. That context raises the priority for anyone managing fleets of Apple devices, especially higher-risk users. Update to the fixed builds, iOS and iPadOS 18.3, the 17.7.6 and earlier-branch releases, and the corresponding macOS, tvOS, watchOS, and visionOS versions, and enforce prompt patching through MDM.
References
- https://support.apple.com/en-us/122066
- https://support.apple.com/en-us/122068
- https://support.apple.com/en-us/122071
- https://support.apple.com/en-us/122072
- https://support.apple.com/en-us/122073
- https://support.apple.com/en-us/122372
- https://support.apple.com/en-us/122374
- https://support.apple.com/en-us/122375
- http://seclists.org/fulldisclosure/2025/Apr/10
- http://seclists.org/fulldisclosure/2025/Apr/5
- http://seclists.org/fulldisclosure/2025/Apr/9
- http://seclists.org/fulldisclosure/2025/Jan/12
- http://seclists.org/fulldisclosure/2025/Jan/13
- http://seclists.org/fulldisclosure/2025/Jan/15
- http://seclists.org/fulldisclosure/2025/Jan/19
- http://seclists.org/fulldisclosure/2025/Jun/19
- http://seclists.org/fulldisclosure/2025/Oct/1
- http://seclists.org/fulldisclosure/2025/Oct/23
- http://seclists.org/fulldisclosure/2025/Oct/30
- http://seclists.org/fulldisclosure/2025/Oct/31
- https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
- https://github.com/cisagov/vulnrichment/issues/194
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24085
Related CVEs
Frequently asked questions
What is CVE-2025-24085?
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
How severe is CVE-2025-24085?
CVE-2025-24085 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2025-24085 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2025-24085?
Public advisories list the following as affected: ipados, iphone os, macos, tvos, visionos, watchos. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-24085?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
