CVE-2025-24257

HIGH

iPadOS < 18.4 - Out-of-bounds Write

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2025-24257. PoCs published by adminlove520, Learningdisordercapital35.

AI-analyzed exploit summary The repository lacks actual exploit code and instead directs users to an external GitHub repository for downloads. It provides generic setup instructions without technical details about the vulnerability or exploit mechanics.

Description

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.

Exploits (2)

github SUSPICIOUS 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-24257

The repository lacks actual exploit code and instead directs users to an external GitHub repository for downloads. It provides generic setup instructions without technical details about the vulnerability or exploit mechanics.

Classification
Suspicious 95%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: Windows (IOGPUFamily kernel memory bug)
No auth needed
Prerequisites: Windows PC · Internet connection · Permission to run files
devstral-2 · analyzed Apr 09, 2026 Full analysis →
nomisec SUSPICIOUS
by Learningdisordercapital35 · poc
https://github.com/Learningdisordercapital35/CVE_2025_24257----NOT-MINE

The repository lacks actual exploit code and instead directs users to an external download link. It provides vague, non-technical instructions for running a PoC without detailing the vulnerability mechanics, affected functions, or exploitation steps.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Unknown
Reliability
Unknown
Target: Windows (IOGPUFamily kernel component)
No auth needed
Prerequisites: Windows PC · Internet connection · Permission to run files
devstral-2 · analyzed Apr 09, 2026 Full analysis →

Scores

CVSS v3 7.1
EPSS 0.0024
EPSS Percentile 14.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (8)
Apple/iOS and iPadOS < 18.4
apple/ipados < 18.4
apple/iphone_os < 18.4
Apple/macOS < 15.4
apple/macos 15.0 - 15.4
apple/visionos < 2.4
Apple/visionOS < 2.4
Apple/watchOS < 11.4
Published Mar 31, 2025
Tracked Since Feb 18, 2026