PT-2025-5297 · Apple · Visionos+9

Desmond

·

Published

2025-01-27

·

Updated

2025-05-01

·

CVE-2025-24123

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions iPadOS versions 17.7.4 and earlier macOS Ventura versions 13.7.3 and earlier macOS Sonoma versions 14.7.3 and earlier visionOS versions 2.3 and earlier iOS versions 18.3 and earlier iPadOS versions 18.3 and earlier macOS Sequoia versions 15.3 and earlier watchOS versions 11.3 and earlier tvOS versions 18.3 and earlier
Description The issue is related to the CoreMedia component of MacOs, iPadOS, visionOS, iOS, watchOS, and tvOS operating systems, which is associated with unlimited resource allocation. Parsing a file may lead to an unexpected app termination. Exploitation of the issue may allow a remote attacker to cause a denial of service.
Recommendations For iPadOS versions 17.7.4 and earlier, update to iPadOS 17.7.4 or later. For macOS Ventura versions 13.7.3 and earlier, update to macOS Ventura 13.7.3 or later. For macOS Sonoma versions 14.7.3 and earlier, update to macOS Sonoma 14.7.3 or later. For visionOS versions 2.3 and earlier, update to visionOS 2.3 or later. For iOS versions 18.3 and earlier, update to iOS 18.3 or later. For iPadOS versions 18.3 and earlier, update to iPadOS 18.3 or later. For macOS Sequoia versions 15.3 and earlier, update to macOS Sequoia 15.3 or later. For watchOS versions 11.3 and earlier, update to watchOS 11.3 or later. For tvOS versions 18.3 and earlier, update to tvOS 18.3 or later.

Fix

DoS

RCE

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-01506
CVE-2025-24123
ZDI-25-168

Affected Products

Coremedia
Apple Macos
Ios
Ipados
Macos Sequoia
Macos Sonoma
Macos Ventura
Tvos
Visionos
Watchos