Who:Apple, Oligo Security researcher Uri Katz, Google’s Threat Analysis Group (TAG), and users of Apple devices.
What:Apple patched a zero-day vulnerability (CVE-2025-24085) affecting multiple Apple devices, including iPhones, Macs, and Apple TVs. The flaw, a use-after-free bug in Core Media, allowed malicious apps to elevate privileges on devices. This vulnerability had been actively exploited in the wild, primarily on iOS versions before 17.2. The update also addressed additional security flaws in AirPlay and CoreAudio components.
How:The vulnerability allowed a malicious app to exploit a flaw in memory management, giving it higher privileges. Apple released updates for iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to fix the issue. Users are advised to apply the updates to prevent exploitation, as the full details of the attacks remain undisclosed.
Read the full article HERE