Sandbox Escape Vulnerability in Apple Products
CVE-2025-24212

6.3MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
31 March 2025

Summary

An app within Apple’s operating systems, such as iOS, macOS, tvOS, and visionOS, may exploit this vulnerability to escape its designated sandbox environment. This can lead to unauthorized access to system resources and potential compromise of user data. Apple has addressed this issue in several updates, emphasizing the importance of keeping devices updated to mitigate associated risks.

Affected Version(s)

iOS and iPadOS < 18.4

iPadOS < 17.7

macOS < 15.4

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.