EXECUTIVE SUMMARY:
Apple has released critical software updates addressing security vulnerabilities across its devices, including a zero-day flaw tracked as CVE-2025-24085, which has been actively exploited in the wild. This vulnerability, a use-after-free bug in the Core Media component, could allow a malicious application on an affected device to escalate privileges. Affected devices include Macs. Additionally, multiple other security issues were addressed, including those related to AirPlay and the CoreAudio component, which could lead to system crashes, denial-of-service attacks, or arbitrary code execution. It could allow remote attackers to execute arbitrary code. Security improvements were made to the Kernel to prevent malicious apps from gaining unauthorized system access.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Apple has released critical software updates addressing security vulnerabilities across its devices, including a zero-day flaw tracked as CVE-2025-24085, which has been actively exploited in the wild. This vulnerability, a use-after-free bug in the Core Media component, could allow a malicious application on an affected device to escalate privileges. Affected devices include Macs. Additionally, multiple other security issues were addressed, including those related to AirPlay and the CoreAudio component, which could lead to system crashes, denial-of-service attacks, or arbitrary code execution. It could allow remote attackers to execute arbitrary code. Security improvements were made to the Kernel to prevent malicious apps from gaining unauthorized system access.[emaillocker id="1283"]
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2025/01/apple-patches-actively-exploited-zero.html