CVE-2025-24257PoC(apple / ipados)

MEDIUMCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An app may be able to cause unexpected system termination or write kernel memory.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Peaked 2d ago at 1 mentions (2026-03-18); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-18: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-20: 1Exploit Tool / Code · 2026-03-18: 1Exploit Tool / Code · 2026-03-19: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 103-1803-1903-20
Signal classification1 categories
PoC
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  •  CrazyMind@CrazyMind90
    PoC

    CVE-2025-24257 — IOGPUFamily kernel heap OOB write on iOS 18.3 .. First public PoC — built entirely with [ClaudeCode] https://github.com/crazymind90/CVE_2025_24257----NOT-MINE

    Post summary

    A public PoC for CVE‑2025‑24257, an iOS 18.3 kernel heap OOB write, has been released on GitHub, but there is no evidence of current exploitation or available patches.

    447022610816.2K
    18.6K followersView on X
  • Hermes Tool@Hermes_tooll
    PoC

    CVE-2025-24257 — IOGPUFamily kernel heap OOB write on iOS 18.3 .. First public PoC — built entirely https://github.com/crazymind90/CVE_2025_24257----NOT-MINE

    Post summary

    The post announces CVE‑2025‑24257, a kernel heap out‑of‑bounds write in iOS 18.3’s IOGPUFamily, and reports that a public proof‑of‑concept is now available via a GitHub repository.

    1130102588.2K
    2.8K followersView on X
  • VulnTracker@vuln_tracker
    PoC

    @Hermes_tooll iOS kernel heap OOB write via IOGPUFamily bitmap_mask underflow - CVE-2025-24257 PoC going public is a big deal for mobile security teams. Time to verify your iOS fleet is patched. Stay on top of Apple vulnerabilities: http://vulntracker.io

    Post summary

    The tweet announces that a PoC for CVE-2025-24257 has been made public and urges iOS security teams to confirm they have applied available patches.

    01010535
    442 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---

Explore more