Skip to content
COOEY

EXPOSURES › CVE-2025-24085

CVE-2025-24085

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-01-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-24085 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedprivilege-escalation

Apple's iOS and macOS products contain a user-after-free vulnerability that allows privilege escalation via malicious applications.

This use-after-free flaw enables privilege escalation in Apple devices, posing a significant risk to DIB organizations relying on Apple hardware for secure environments. While not directly linked to ransomware, the vulnerability's presence in widely deployed products increases the attack surface for supply-chain and device-based compromises. DIB orgs must verify patch status and restrict untrusted app execution on affected devices.

Shame score — A known privilege escalation vulnerability in widely deployed consumer hardware that requires vendor patching rather than a negligent disclosure or default credential failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.