Logic Issue in Apple Products Leading to Potential Disclosure of Process Memory
CVE-2025-24194

6.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
31 March 2025

Summary

A logic issue in Apple products has been identified, which was mitigated with enhanced verification processes. This vulnerability may allow maliciously crafted web content to trigger the unintended disclosure of sensitive process memory, potentially exposing user data or system information. The issue has been addressed in multiple versions of Apple's operating systems, reinforcing security measures to protect users from exploitation.

Affected Version(s)

iOS and iPadOS < 18.4

macOS < 15.4

tvOS < 18.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.