CVE-2025-24252Active Exploitation(apple / ipados)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Active Exploitation · 2026-03-08: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-08: 103-0803-09
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-081
Active Exploitation1
2026-03-091
General1
Full discourse2 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-1086 2 - CVE-2022-40982 3 - CVE-2025-24252 4 - CVE-2025-55182 5 - CVE-2026-21533 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists a set of trending CVE identifiers with no additional technical, exploit, or mitigation information.

    00020213
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    Attackers on the same Wi-Fi network send crafted AirPlay packets exploiting bugs like use-after-free (e.g., CVE-2025-24252) or buffer overflows in the protocol/SDK. This enables zero-click remote code execution—no interaction needed—letting them install malware, read files, or steal data on vulnerable devices. It's wormable, so it can spread across the network. Apple patched it fully in iOS 18.4+ (March 2025). If updated, you're protected. Check Settings > General > Software Update.

    Post summary

    CVE‑2025‑24252 is actively exploited via zero‑click, wormable AirPlay packets, enabling remote code execution on vulnerable devices; Apple has fixed the issue in iOS 18.4+.

    0000078
    8.4M followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---

Explore more