Description
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause an unexpected app termination.
Published: 2025-01-27
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A type‑confusion flaw in several Apple operating systems allows a local network attacker to trigger an unexpected application termination, resulting in a denial‑of‑service condition. The vulnerability arises from improper type validation during execution, as identified by CWE‑843, and can cause an application to crash when it encounters a maliciously crafted packet on the local network.

Affected Systems

Affected products include Apple iOS, iPadOS, macOS, tvOS, and visionOS on the following releases: iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, and visionOS 2.3. Devices running any earlier firmware versions that lack the patch remain vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact, while the EPSS score of 1% suggests that widespread exploitation is currently unlikely. The flaw requires the attacker to be on the same local network as the target device and to deliver a specially crafted packet that triggers the type‑confusion path; thus the risk is confined to environments where the device is exposed to untrusted local traffic. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on June 18, 2026 at 03:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the patched Apple operating system releases: iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, and visionOS 2.3.
  • Restrict the device to trusted local networks or isolate it from untrusted wireless connections to prevent the triggering packet from reaching the application.
  • Configure the device’s firewall to block unwanted incoming connections and monitor for anomalous traffic patterns.

Generated by OpenCVE AI on June 18, 2026 at 03:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3639 A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.
History

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Network Type‑Confusion Vulnerability Causing App Crashes

Tue, 16 Jun 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Network Type Confusion Exploit Causes Application Crash

Tue, 28 Apr 2026 04:30:00 +0000

Type Values Removed Values Added
Title Local Network Type Confusion Exploit Causes Application Crash

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination. A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the local network may cause an unexpected app termination.
References

Mon, 03 Nov 2025 21:30:00 +0000


Fri, 31 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jan 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Apple watchos
Weaknesses CWE-843
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Apple watchos
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Mon, 27 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description A type confusion issue was addressed with improved checks. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A remote attacker may cause an unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:09:11.884Z

Reserved: 2025-01-17T00:00:44.973Z

Link: CVE-2025-24129

cve-icon Vulnrichment

Updated: 2025-11-03T21:03:07.665Z

cve-icon NVD

Status : Modified

Published: 2025-01-27T22:15:17.887

Modified: 2026-06-17T08:58:08.500

Link: CVE-2025-24129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T03:15:04Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')