Skip to main content

Security updates include remediation for exploited vulnerability CVE-2025-24201, which affects iOS, iPadOS, and macOS

Summary

Security updates include remediation for exploited vulnerability CVE-2025-24201, which affects iOS, iPadOS, and macOS 

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Apple has released security updates to address an exploited vulnerability in multiple Apple products. CVE-2025-24201 is an 'out-of-bounds write' vulnerability that could allow an attacker with maliciously crafted web content to break out of Web Content sandbox.

The security update addressing CVE-2025-24201 is a supplementary fix for an exploited vulnerability that was addressed in iOS 17.2. Apple is aware of a report that 'this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2'.

Remediation advice

Affected organisations are encouraged to review Apple security releases and apply the relevant updates.

Remediation steps

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 12 March 2025 4:34 pm