Skip to main content

Security updates include remediation for an exploited zero-day privilege escalation vulnerability affecting iOS, iPadOS, and macOS

Summary

Security updates include remediation for an exploited zero-day privilege escalation vulnerability affecting iOS, iPadOS, and macOS 

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Apple has released security updates to address 70 named vulnerabilities in multiple Apple products, including the exploited zero-day privilege escalation vulnerability CVE-2025-24085.

CVE-2025-24085 is a 'use after free' vulnerability with a CVSSv3 base score of 7.8. Apple reports that CVE-2025-24085 may have been exploited by attackers against versions of iOS before 17.2.

Threat updates

Remediation advice

Affected organisations are encouraged to review Apple security releases and apply the relevant updates.

Remediation steps

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 29 January 2025 12:32 pm