Description
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause an unexpected app termination.
Published: 2025-01-27
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Application Crash)
Action: Patch Immediately
AI Analysis

Impact

A type‑confusion flaw in several Apple operating systems allows a local network attacker to trigger an unexpected application termination, resulting in a denial‑of‑service condition. The vulnerability arises from improper type validation during execution, as identified by CWE‑843.

Affected Systems

Affected products include Apple iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, and visionOS 2.3. Devices running these OS versions are vulnerable until patched; watchOS is not listed as having a fix in the advisory.

Risk and Exploitability

The CVSS score of 7.5 reflects a significant impact, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation at present. The flaw requires an attacker to be on the local network and to deliver the triggering payload, so the risk is contained to environments where the device is exposed to untrusted local traffic. The vulnerability is not yet catalogued in CISA’s KEV list.

Generated by OpenCVE AI on April 28, 2026 at 04:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the affected Apple operating systems to the patched releases (iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3).
  • Limit the device to trusted local networks or isolate it from untrusted wireless connections to prevent the type‑confusion trigger from reaching the application.
  • Follow the Apple support links provided for step‑by‑step update instructions and to verify the issue is resolved.

Generated by OpenCVE AI on April 28, 2026 at 04:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3639 A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.
History

Tue, 28 Apr 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local Network Type Confusion Exploit Causes Application Crash

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination. A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause an unexpected app termination.
References

Mon, 03 Nov 2025 21:30:00 +0000


Fri, 31 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Apple watchos
Weaknesses CWE-843
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Apple watchos
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Mon, 27 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:09:11.884Z

Reserved: 2025-01-17T00:00:44.973Z

Link: CVE-2025-24129

cve-icon Vulnrichment

Updated: 2025-11-03T21:03:07.665Z

cve-icon NVD

Status : Modified

Published: 2025-01-27T22:15:17.887

Modified: 2026-04-02T19:19:04.423

Link: CVE-2025-24129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:15:16Z

Weaknesses