CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2025-24194

    Last Modified: 2 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may result in the disclosure of process memory.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-30456

    Last Modified: 28 Apr 2026

    A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

    Published: 31 Mar 2025
    7.4
    High

    CVE-2025-24229

    Last Modified: 28 Apr 2026

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A sandboxed app may be able to access sensitive user data.

    Published: 31 Mar 2025
    5.6
    Medium

    CVE-2025-24157

    Last Modified: 2 Apr 2026

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 31 Mar 2025
    5
    Medium

    CVE-2025-24248

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to enumerate devices that have signed into the user's Apple Account.

    Published: 31 Mar 2025
    7.4
    High

    CVE-2025-30437

    Last Modified: 28 Apr 2026

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to corrupt coprocessor memory.

    Published: 31 Mar 2025
    7.4
    High

    CVE-2025-30460

    Last Modified: 28 Apr 2026

    A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

    Published: 31 Mar 2025
    7
    High

    CVE-2025-24209

    Last Modified: 2 Apr 2026

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash.

    Published: 31 Mar 2025
    6.6
    Medium

    CVE-2025-24198

    Last Modified: 28 Apr 2026

    This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An attacker with physical access may be able to use Siri to access sensitive user data.

    Published: 31 Mar 2025
    7
    High

    CVE-2024-54533

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.

    Published: 31 Mar 2025
    6.8
    Medium

    CVE-2025-24272

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24264

    Last Modified: 2 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24233

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to read or write to protected files.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24232

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access arbitrary files.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24265

    Last Modified: 28 Apr 2026

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24273

    Last Modified: 28 Apr 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination or corrupt kernel memory.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24199

    Last Modified: 28 Apr 2026

    An uncontrolled format string issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause a denial-of-service.

    Published: 31 Mar 2025
    6.1
    Medium

    CVE-2025-24208

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30461

    Last Modified: 28 Apr 2026

    An access issue was addressed with additional sandbox restrictions on the system pasteboards. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24249

    Last Modified: 2 Apr 2026

    A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to check the existence of an arbitrary path on the file system.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30441

    Last Modified: 28 Apr 2026

    This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24269

    Last Modified: 28 Apr 2026

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to cause unexpected system termination.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-24228

    Last Modified: 28 Apr 2026

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to execute arbitrary code with kernel privileges.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30457

    Last Modified: 28 Apr 2026

    This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to create symlinks to protected regions of the disk.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24253

    Last Modified: 28 Apr 2026

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24195

    Last Modified: 28 Apr 2026

    An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A user may be able to elevate privileges.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24204

    Last Modified: 18 Jun 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.

    Published: 31 Mar 2025
    6.3
    Medium

    CVE-2025-24212

    Last Modified: 28 Apr 2026

    This issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to break out of its sandbox.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24245

    Last Modified: 28 Apr 2026

    This issue was addressed by adding a delay between verification code attempts. This issue is fixed in macOS Sequoia 15.4. A malicious app may be able to access a user's saved passwords.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-31183

    Last Modified: 28 Apr 2026

    The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30454

    Last Modified: 28 Apr 2026

    A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. A malicious app may be able to access private information.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24250

    Last Modified: 28 Apr 2026

    This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app acting as a HTTPS proxy could get access to sensitive user data.

    Published: 31 Mar 2025
    8.8
    High

    CVE-2025-24196

    Last Modified: 28 Apr 2026

    A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An attacker with user privileges may be able to read kernel memory.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24207

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to enable iCloud storage features without user consent.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24211

    Last Modified: 18 Jun 2026

    This issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24246

    Last Modified: 2 Apr 2026

    An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access user-sensitive data.

    Published: 31 Mar 2025
    4.6
    Medium

    CVE-2025-30439

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. An attacker with physical access to a locked device may be able to view sensitive user information.

    Published: 31 Mar 2025
    8.1
    High

    CVE-2025-24180

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, visionOS 2.4, watchOS 11.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24231

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24266

    Last Modified: 28 Apr 2026

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30458

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4. An app may be able to read files outside of its sandbox.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-30462

    Last Modified: 28 Apr 2026

    A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. Apps that appear to use App Sandbox may be able to launch without restrictions.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30435

    Last Modified: 28 Apr 2026

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.4. A sandboxed app may be able to access sensitive user data in system logs.

    Published: 31 Mar 2025
    5
    Medium

    CVE-2025-30434

    Last Modified: 28 Apr 2026

    The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30463

    Last Modified: 28 Apr 2026

    The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-24226

    Last Modified: 28 Apr 2026

    The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.

    Published: 31 Mar 2025
    7.8
    High

    CVE-2025-24267

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to gain root privileges.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24230

    Last Modified: 18 Jun 2026

    An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Playing a malicious audio file may lead to an unexpected app termination.

    Published: 31 Mar 2025
    5.5
    Medium

    CVE-2025-30438

    Last Modified: 28 Apr 2026

    This issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started.

    Published: 31 Mar 2025
    9.8
    Critical

    CVE-2025-24181

    Last Modified: 28 Apr 2026

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.

    Published: 31 Mar 2025