Raleigh, NC

32°F
Scattered Clouds Humidity: 79%
Wind: 2.06 M/S

Apple Releases Critical Fixes for Three Recent Zero-Days Affecting Older iOS and macOS Devices

Apple Releases Critical Fixes for Three Recent Zero-Days Affecting Older iOS and macOS Devices

Apple Releases Security Updates for Older Devices to Address Actively Exploited Vulnerabilities 

On Monday, Apple rolled out security patches for three vulnerabilities that have been actively exploited, extending fixes to older device models and previous operating system versions. 

Details of the Vulnerabilities 

The patched vulnerabilities include: 

CVE-2025-24085 (CVSS Score: 7.3) – A use-after-free flaw in the Core Media component, allowing a pre-installed malicious application to escalate privileges. 

CVE-2025-24200 (CVSS Score: 4.6) – An authorization flaw in the Accessibility component, which could enable an attacker to disable USB Restricted Mode on a locked device, facilitating cyber-physical attacks. 

CVE-2025-24201 (CVSS Score: 8.8) – An out-of-bounds write issue in the WebKit component, potentially allowing an attacker to create malicious web content capable of escaping the Web Content sandbox. 

Fixed Versions 

Apple has addressed these vulnerabilities in the following software updates: 

CVE-2025-24085 – Resolved in macOS Sonoma 14.7.5, macOS Ventura 13.7.5, and iPadOS 17.7.6. 

CVE-2025-24200 & CVE-2025-24201 – Fixed in iOS 15.8.4, iPadOS 15.8.4, iOS 16.7.11, and iPadOS 16.7.11. 

Affected Devices 

The fixes apply to the following Apple devices: 

iOS 15.8.4 / iPadOS 15.8.4: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st gen), iPad Air 2, iPad mini (4th gen), and iPod touch (7th gen). 

iOS 16.7.11 / iPadOS 16.7.11: iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th gen, iPad Pro 9.7-inch, and iPad Pro 12.9-inch (1st gen). 

iPadOS 17.7.6: iPad Pro 12.9-inch (2nd gen), iPad Pro 10.5-inch, and iPad 6th gen. 

Additional Security Updates 

In parallel, Apple also released major updates for newer systems, addressing a broad range of vulnerabilities: 

  • iOS 18.4 & iPadOS 18.4 – 62 security fixes 
  • macOS Sequoia 15.4 – 131 security fixes 
  • tvOS 18.4 – 36 security fixes 
  • visionOS 2.4 – 38 security fixes 
  • Safari 18.4 – 14 security fixes 

While the latest vulnerabilities had already been exploited in the wild, there are no reports of active attacks targeting the newly disclosed flaws. However, users are strongly advised to update their devices to the latest versions to protect against potential threats. 

Found this article interesting? Follow us on X(Twitter)  and FaceBook to read more exclusive content we post. 

Image

With Cybersecurity Insights, current news and event trends will be captured on cybersecurity, recent systems / cyber-attacks, artificial intelligence (AI), technology innovation happening around the world; to keep our viewers fast abreast with the current happening with technology, system security, and how its effect our lives and ecosystem. 

Please fill the required field.