An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Playing a malicious audio file may lead to an unexpected app termination.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 03 Nov 2025 21:30:00 +0000
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Mon, 07 Apr 2025 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Apple
         Apple ipados Apple iphone Os Apple macos Apple tvos Apple visionos  | 
|
| CPEs | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Apple
         Apple ipados Apple iphone Os Apple macos Apple tvos Apple visionos  | 
Thu, 03 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Wed, 02 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-125 | |
| Metrics | 
        
        cvssV3_1
         
  | 
Mon, 31 Mar 2025 22:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Playing a malicious audio file may lead to an unexpected app termination. | |
| References | 
         | 
Status: PUBLISHED
Assigner: apple
Published: 2025-03-31T22:23:03.205Z
Updated: 2025-11-03T21:09:29.374Z
Reserved: 2025-01-17T00:00:45.005Z
Link: CVE-2025-24230
Updated: 2025-04-02T13:21:32.853Z
Status : Modified
Published: 2025-03-31T23:15:20.273
Modified: 2025-11-03T21:19:36.510
Link: CVE-2025-24230
No data.
ReportizFlow