5

CVE-2025-24097

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.7, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to read arbitrary file metadata.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ iPadOS Version < 18.4
Apple ≫ iPhone OS Version < 18.4
Apple ≫ macOS Version < 14.7.5
Apple ≫ macOS Version < 15.4
Apple ≫ tvOS Version < 18.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.274
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5 1.3 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://support.apple.com/en-us/122374
Vendor Advisory
Release Notes
https://support.apple.com/en-us/122371
Vendor Advisory
Release Notes
https://support.apple.com/en-us/122373
Vendor Advisory
Release Notes
https://support.apple.com/en-us/122377
Vendor Advisory
Release Notes
https://support.apple.com/en-us/122376
https://support.apple.com/en-us/122405
http://seclists.org/fulldisclosure/2025/Apr/13
http://seclists.org/fulldisclosure/2025/May/6
http://seclists.org/fulldisclosure/2025/Apr/8
http://seclists.org/fulldisclosure/2025/Apr/11
http://seclists.org/fulldisclosure/2025/Apr/4
http://seclists.org/fulldisclosure/2025/Apr/9