Cyber Posture

CVE-2025-24159

High

Published: 27 January 2025

Published
27 January 2025
Modified
02 April 2026
KEV Added
Patch
CVSS Score 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0005 14.2th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.

Security Summary

CVE-2025-24159 is a validation issue addressed through improved logic in multiple Apple operating systems, enabling an app to execute arbitrary code with kernel privileges. The vulnerability affects iOS prior to version 18.3, iPadOS prior to 18.3 or 17.7.4, macOS Sequoia prior to 15.3, macOS Sonoma prior to 14.7.3, tvOS prior to 18.3, visionOS prior to 2.3, and watchOS prior to 11.3. It has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is associated with CWE-94 (code injection), though NVD provides no additional CWE details.

Exploitation requires a local attacker with low-complexity access and no privileges, but user interaction is necessary. Successful exploitation grants kernel-level code execution, resulting in high impacts to confidentiality, integrity, and availability, potentially allowing full system compromise on affected devices.

Apple security advisories recommend updating to the fixed versions: iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, or watchOS 11.3. Detailed patch information is available in the referenced support articles at https://support.apple.com/en-us/122066, https://support.apple.com/en-us/122067, https://support.apple.com/en-us/122068, https://support.apple.com/en-us/122069, and https://support.apple.com/en-us/122071.

Details

CWE(s)
NVD-CWE-noinfoCWE-94

Affected Products

apple
ipados
≤ 17.7.4 · 18.0 — 18.3
apple
iphone os
≤ 18.3
apple
macos
≤ 14.7.3 · 15.0 — 15.3
apple
tvos
≤ 18.3
apple
visionos
≤ 2.3
apple
watchos
≤ 11.3

MITRE ATT&CK Enterprise Techniques

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

The vulnerability is a local code injection flaw (CWE-94) that allows an unprivileged app to execute arbitrary code with kernel privileges on Apple platforms, directly mapping to exploitation for privilege escalation.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References