PT-2025-18064 · Apple · Ipados+1

Guilherme Rambo

·

Published

2025-04-28

·

Updated

2025-06-25

·

CVE-2025-24091

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iOS versions prior to 18.3 iPadOS versions prior to 18.3 iPadOS versions prior to 17.7.3
Description An app could impersonate system notifications, and sensitive notifications now require restricted entitlements. This issue could allow an app to cause a denial-of-service. The vulnerability exploits the Darwin notification system’s lack of sender verification.
Recommendations For iOS versions prior to 18.3, update to iOS 18.3 or later to resolve the issue. For iPadOS versions prior to 18.3, update to iPadOS 18.3 or later to resolve the issue. For iPadOS versions prior to 17.7.3, update to iPadOS 17.7.3 or later to resolve the issue. As a temporary workaround, consider restricting app and widget installs via Mobile Device Manager until the update is applied.

Fix

DoS

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2025-09510
CVE-2025-24091

Affected Products

Ios
Ipados