CVE-2025-24085

CRITICAL KEV

iPadOS < 17.7.6 - Use-After-Free

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-24085 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added January 29, 2025. EIP tracks 3 public exploits from researchers including Mohammed Idrees Banyamer, JGoyd, 5ky9uy.

AI-analyzed exploit summary This exploit leverages a vulnerable macOS LaunchDaemon plist configuration to execute arbitrary commands with root privileges. It creates a root payload script that adds a root shell binary, creates an admin user, and installs a persistent LaunchDaemon backdoor for root access.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.

Exploits (3)

exploitdb WORKING POC
by Mohammed Idrees Banyamer · pythonlocalmacos
https://www.exploit-db.com/exploits/52316

This exploit leverages a vulnerable macOS LaunchDaemon plist configuration to execute arbitrary commands with root privileges. It creates a root payload script that adds a root shell binary, creates an admin user, and installs a persistent LaunchDaemon backdoor for root access.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: macOS Sonoma (14.x ARM64 / x86_64)
Auth required
Prerequisites: Local access to the target system · Ability to write to /Library/LaunchDaemons/ · Ability to execute commands with sudo privileges
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 30 stars
by JGoyd · poc
https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201

This repository contains a detailed writeup of the Glass Cage exploit chain targeting iOS 18.2.1, which involves a zero-click PNG-based attack leveraging CVE-2025-24085 (Core Media privilege escalation) and CVE-2025-24201 (WebKit RCE). The attack chain is described as being used in the wild and includes steps for achieving root access and persistence.

Classification
Writeup 100%
Attack Type
Rce | Lpe
Complexity
Complex
Reliability
Reliable
Target: iOS 18.2.1
No auth needed
Prerequisites: Malicious PNG image sent via iMessage · Target device running iOS 18.2.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WRITEUP 4 stars
by 5ky9uy · poc
https://github.com/5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201

This repository contains a detailed technical analysis of a zero-click RCE exploit chain (CVE-2025-24085 and CVE-2025-24201) targeting iOS 18.2.1 via malicious PNG files sent through iMessage. The report includes exploit chain breakdown, log evidence, and mitigation recommendations.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: iOS 18.2.1 (iPhone 14 Pro Max)
No auth needed
Prerequisites: iOS 18.2.1 device · iMessage delivery vector · malicious PNG file
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (23)

Core 23
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122066
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122068
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122071
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122072
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122073
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Apr/10
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Apr/5
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Apr/9
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jan/12
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jan/13
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jan/15
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jan/19
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Jun/19
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Oct/1
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Oct/23
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Oct/30
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2025/Oct/31

Scores

CVSS v3 10.0
EPSS 0.1307
EPSS Percentile 94.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2025-01-29
VulnCheck KEV 2025-01-27
ENISA EUVD EUVD-2025-3607
CWE
CWE-416
Status published
Products (14)
Apple/iOS and iPadOS < 18.3
apple/ipados < 17.7.6
Apple/iPadOS < 17.7.6
apple/iphone_os < 18.3
apple/macos < 13.7.5
Apple/macOS < 13.7.5
Apple/macOS < 14.7.5
Apple/macOS < 15.3
apple/tvos < 18.3
Apple/tvOS < 18.3
... and 4 more
Published Jan 27, 2025
KEV Added Jan 29, 2025
Tracked Since Feb 18, 2026