CVE-2024-54525

HIGH

Apple Ipados < 18.2 - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

A logic issue was addressed with improved file handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.

References (5)

Core 5
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121837
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121839
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121843
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121844
Release Notes, Vendor Advisory
https://support.apple.com/en-us/121845

Scores

CVSS v3 8.8
EPSS 0.0146
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (11)
Apple/iOS and iPadOS < 18.2
apple/ipados < 18.2
apple/iphone_os < 18.2
apple/macos < 15.2
Apple/macOS < 15.2
apple/tvos < 18.2
Apple/tvOS < 18.2
apple/visionos < 2.2
Apple/visionOS < 2.2
apple/watchos < 11.2
... and 1 more
Published Mar 17, 2025
Tracked Since Feb 18, 2026