CVE-2025-24149: An out-of-bounds read was addressed with improved bounds checking.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Parsing a file may lead to disclosure of user information.
Security readout for executives and security teams
Plain-English summary
CVE-2025-24149 is an Apple file-parsing flaw that could expose user information when a person opens or processes a crafted file. Apple fixed it across current iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch operating systems. The issue matters most for privacy risk on unmanaged or slow-to-update Apple devices.
Executive priority
Schedule normal-priority remediation, with faster action for executives, legal, finance, and other privacy-sensitive users. This is not supported as actively exploited in the provided sources, but it affects many Apple platforms and has high confidentiality impact.
Technical view
The issue is a CWE-125 out-of-bounds read in Apple software. The CVSS vector is local, low complexity, no privileges required, user interaction required, with high confidentiality impact and no integrity or availability impact. Apple says improved bounds checking resolves the flaw in the listed fixed OS releases.
Likely exposure
Exposure is likely limited to Apple devices running versions older than iOS/iPadOS 18.3, iPadOS 17.7.4, macOS 15.3, 14.7.3, 13.7.3, tvOS 18.3, visionOS 2.3, or watchOS 11.3. Exact affected pre-fix version ranges are not provided in the bundle.
Exploitation context
The bundle does not show CISA KEV listing or cited evidence of active exploitation. The attack requires user interaction with a file and may disclose user information. No public exploit status is established by the provided sources.
Researcher notes
The public detail is limited: Apple describes an out-of-bounds read fixed by bounds checking and states file parsing may disclose user information. The bundle does not identify the parser component, vulnerable file type, proof of concept, or exact affected version ranges.
Mitigation direction
Update Apple devices to the fixed OS releases or later.
Prioritize managed devices handling sensitive files or external attachments.
Use MDM compliance checks to block outdated Apple OS versions.
Review Apple advisories for any later product-specific guidance.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-125 · source CWE mapping
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.