Type Confusion Vulnerability in Apple Operating Systems
CVE-2025-24137

8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
27 January 2025

Summary

A type confusion vulnerability in Apple's operating systems allows remote attackers to exploit specific application flaws. Through this vulnerability, an attacker may induce unexpected application termination or execute arbitrary code. Apple has implemented improved validation measures to address this issue across various OS versions, enhancing the overall security posture.

Affected Version(s)

iOS and iPadOS < 18.3

iPadOS < 17.7

macOS < 14.7

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.