Logic Issue in Apple Products Leading to Potential Disclosure of Process Memory
CVE-2025-24194
6.5MEDIUM
Key Information:
- Vendor
- Apple
- Vendor
- CVE Published:
- 31 March 2025
Summary
A logic issue in Apple products has been identified, which was mitigated with enhanced verification processes. This vulnerability may allow maliciously crafted web content to trigger the unintended disclosure of sensitive process memory, potentially exposing user data or system information. The issue has been addressed in multiple versions of Apple's operating systems, reinforcing security measures to protect users from exploitation.
Affected Version(s)
iOS and iPadOS < 18.4
macOS < 15.4
tvOS < 18.4
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved