Description
The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tvOS 18.3, tvOS 18.4, visionOS 2.3, visionOS 2.4, watchOS 11.3, watchOS 11.4. Parsing a file may lead to an unexpected app termination.
Published: 2025-01-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unexpected app termination (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

A flaw in how Apple operating systems parse certain file formats can cause an application that processes such a file to terminate unexpectedly. The crash leads to a temporary denial of service for the affected application and, in some contexts, can affect overall system stability if the crashed app is critical. The underlying weakness is a lack of adequate bounds or validity checks during parsing, consistent with a classic resource misuse or improper handling error.

Affected Systems

The vulnerability affects Apple iOS and iPadOS on devices running iOS 18.3, 18.4, iPadOS 18.3, 18.4, and iPadOS 17.7.4; macOS on Sequoia 15.3 and 15.4, and Sonoma 14.7.3; tvOS 18.3 and 18.4; visionOS 2.3 and 2.4; watchOS 11.3 and 11.4. It has been fixed in these released versions.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate severity. The EPSS score of less than 1% means the likelihood of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw can be triggered by supplying a crafted file to any application that performs the vulnerable parsing in the affected OS. The attack vector is likely local or remote file delivery to an app; no confirmed remote code execution or privilege escalation is reported. The risk is therefore moderate, chiefly as a Denial‑of‑Service concern.

Generated by OpenCVE AI on April 28, 2026 at 04:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to an OS version that includes the fix (e.g., iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4, Sonoma 14.7.3, tvOS 18.4, visionOS 2.4, or watchOS 11.4).
  • If upgrading is not immediately possible, avoid opening files from untrusted sources until the patch is applied.
  • Temporarily disable any in‑app file import functionalities or set the system to require user confirmation before opening files that may be vulnerable.

Generated by OpenCVE AI on April 28, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3665 The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.
History

Tue, 28 Apr 2026 04:30:00 +0000

Type Values Removed Values Added
Title App Crash Due to File Parsing Vulnerability Across Apple Platforms
Weaknesses CWE-416

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination. The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tvOS 18.3, tvOS 18.4, visionOS 2.3, visionOS 2.4, watchOS 11.3, watchOS 11.4. Parsing a file may lead to an unexpected app termination.
References

Mon, 03 Nov 2025 21:30:00 +0000


Mon, 03 Nov 2025 20:30:00 +0000

Type Values Removed Values Added
References

Mon, 03 Mar 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Apple watchos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
Apple watchos
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Tue, 18 Feb 2025 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 28 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sonoma 14.7.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Parsing a file may lead to an unexpected app termination.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:15:06.650Z

Reserved: 2025-01-17T00:00:44.988Z

Link: CVE-2025-24163

cve-icon Vulnrichment

Updated: 2025-11-03T21:05:32.167Z

cve-icon NVD

Status : Modified

Published: 2025-01-27T22:15:20.267

Modified: 2026-04-02T19:19:10.437

Link: CVE-2025-24163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:15:16Z

Weaknesses