CISA Known Exploited Vulnerability (KEV)
Apple Multiple Products Use-After-Free Vulnerability
January 29, 2025
February 19, 2025
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-416 |
Use After Free |