Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.
Published: 2025-04-29
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption (potential local code execution)
Action: Patch Immediately
AI Analysis

Impact

A use‑after‑free bug allows a local‑network attacker to corrupt the memory of a running process on Apple devices. The corrupted memory could be used to overwrite data, manipulate program flow, or ultimately execute arbitrary code or tamper with sensitive information. This vulnerability is catalogued as CWE‑416.

Affected Systems

Apple iOS (18.4 and later), iPadOS (18.4 and later or 17.7.6 and later), macOS Sequoia (15.4 and later), macOS Sonoma (14.7.5 and later), macOS Ventura (13.7.5 and later), tvOS (18.4 and later), and visionOS (2.4 and later). Devices running earlier firmware are vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity rating, but the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attacks would require the adversary to be on the same local network segment as the vulnerable device, which can be difficult to achieve remotely. While the likelihood is low, the potential impact is significant due to the possibility of arbitrary code execution.

Generated by OpenCVE AI on April 28, 2026 at 02:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the device to iOS 18.4 or later, iPadOS 18.4 or 17.7.6 or later, macOS Sequoia 15.4 or later, macOS Sonoma 14.7.5 or later, macOS Ventura 13.7.5 or later, tvOS 18.4 or later, or visionOS 2.4 or later. Apple’s official software updates contain the memory‑management fix that eliminates the use‑after‑free flaw.
  • If an immediate OS upgrade is not possible, isolate the device from untrusted local‑network traffic. Apply network segmentation, firewall rules, or Wi‑Fi isolation to prevent an attacker from reaching the device over the local network.
  • Continuously monitor the device for anomalous memory behavior or unexpected process crashes, as these may indicate an attempt to exploit the flaw. Keep the device’s operating system and all security layers up to date to reduce the window of exposure.

Generated by OpenCVE AI on April 28, 2026 at 02:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14858 A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.
History

Tue, 28 Apr 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Network Use‑After‑Free Causing Memory Corruption on Apple Devices

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory. A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.

Fri, 07 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple tvos
Apple visionos

Tue, 29 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Apr 2025 02:30:00 +0000

Type Values Removed Values Added
Description A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:21:57.464Z

Reserved: 2025-01-17T00:00:45.010Z

Link: CVE-2025-24252

cve-icon Vulnrichment

Updated: 2025-04-29T13:26:40.902Z

cve-icon NVD

Status : Modified

Published: 2025-04-29T03:15:34.600

Modified: 2026-04-02T19:19:27.833

Link: CVE-2025-24252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T02:15:18Z

Weaknesses