EXPOSURES › CVE-2025-24085
CVE-2025-24085
HIGH ⌖ ON CISA KEV · EXPLOITEDApple's iOS and macOS products contain a user-after-free vulnerability that allows privilege escalation via malicious applications.
This use-after-free flaw enables privilege escalation in Apple devices, posing a significant risk to DIB organizations relying on Apple hardware for secure environments. While not directly linked to ransomware, the vulnerability's presence in widely deployed products increases the attack surface for supply-chain and device-based compromises. DIB orgs must verify patch status and restrict untrusted app execution on affected devices.
Shame score — A known privilege escalation vulnerability in widely deployed consumer hardware that requires vendor patching rather than a negligent disclosure or default credential failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.