CVE-2025-24107

HIGH

iPadOS < 18.3 - Unauthenticated Privilege Escalation to Root via Permissions Issue

Title source: llm
STIX 2.1

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, watchOS 11.3. A malicious app may be able to gain root privileges.

References (7)

Core 7

Scores

CVSS v3 7.8
EPSS 0.0021
EPSS Percentile 11.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (9)
Apple/iOS and iPadOS < 18.3
apple/ipados < 18.3
apple/iphone_os < 18.3
apple/macos < 15.3
Apple/macOS < 15.3
apple/tvos < 18.3
Apple/tvOS < 18.3
apple/watchos < 11.3
Apple/watchOS < 11.3
Published Jan 27, 2025
Tracked Since Feb 18, 2026