{"id":2975,"date":"2025-04-01T10:04:16","date_gmt":"2025-04-01T10:04:16","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/01\/apple-warns-of-three-0-day-vulnerabilities-actively-exploited-in-attacks\/"},"modified":"2025-04-01T10:04:16","modified_gmt":"2025-04-01T10:04:16","slug":"apple-warns-of-three-0-day-vulnerabilities-actively-exploited-in-attacks","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/01\/apple-warns-of-three-0-day-vulnerabilities-actively-exploited-in-attacks\/","title":{"rendered":"Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks"},"content":{"rendered":"<p>    Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Apple has issued an urgent security advisory concerning three critical zero-day vulnerabilities <a href=\"https:\/\/cybersecuritynews.com\/apple-webkit-zero-day-vulnerability-actively-exploit-in-high-profile-cyber-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-24200<\/a>, <a href=\"https:\/\/cybersecuritynews.com\/apple-webkit-zero-day-vulnerability-actively-exploit-in-high-profile-cyber-attacks\/\">CVE-2025-24201<\/a>, and <a href=\"https:\/\/cybersecuritynews.com\/apple-zero-day-vulnerability-iphone-users\/\">CVE-2025-24085<\/a> that have been actively exploited in sophisticated attacks.\u00a0<\/p>\n<p>These vulnerabilities affect a wide range of Apple devices, including <a href=\"https:\/\/cybersecuritynews.com\/apple-fixes-zero-day-flaw\/\" target=\"_blank\" rel=\"noreferrer noopener\">iPhones, iPads, Macs<\/a>, and other platforms. Users are strongly advised to update their devices immediately to mitigate potential security risks.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Significant Vulnerabilities Under Active Exploitation<\/strong><\/h2>\n<h3 class=\"wp-block-heading\"><strong>CVE-2025-24200<\/strong><\/h3>\n<p>The first vulnerability, tracked as CVE-2025-24200, is an authorization flaw that can be exploited in a physical attack to disable USB Restricted Mode on a locked device.\u00a0<\/p>\n<p>According to Apple\u2019s advisory, this vulnerability \u201cmay have been exploited in an extremely sophisticated attack against specific targeted individuals\u201d.\u00a0<\/p>\n<p>The flaw was discovered and reported by Bill Marczak of The Citizen Lab at The University of Toronto\u2019s Munk School.<\/p>\n<p>A malicious actor can disable USB Restricted Mode on a locked device as part of a cyber-physical attack.\u00a0<\/p>\n<p>USB Restricted Mode, introduced in iOS 11.4.1, prevents iOS and iPadOS devices from communicating with connected accessories if the device hasn\u2019t been unlocked within the past hour \u2013 a critical security feature designed to thwart forensic tools.<\/p>\n<h3 class=\"wp-block-heading\"><strong>CVE-2025-24201<\/strong><\/h3>\n<p>The second vulnerability, CVE-2025-24201, affects <a href=\"https:\/\/cybersecuritynews.com\/cisa-warns-of-apple-webkit-out-of-bounds-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">WebKit<\/a>, the browser engine powering Safari and many iOS applications.\u00a0<\/p>\n<p>This out-of-bounds write issue could allow maliciously crafted web content to break out of the Web Content sandbox.<\/p>\n<p>Apple describes this as \u201ca supplementary fix for an attack that was blocked in iOS 17.2\u201d and acknowledges that it \u201cmay have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2\u201d.<\/p>\n<h3 class=\"wp-block-heading\"><strong>CVE-2025-24085<\/strong><\/h3>\n<p>The third zero-day, CVE-2025-24085, is a use-after-free vulnerability in the CoreMedia component \u2013 a framework that manages audio and video playback across Apple products.\u00a0<\/p>\n<p>As detailed in Apple\u2019s advisory, \u201cA malicious application may be able to elevate privileges\u201d. This vulnerability affects multiple Apple operating systems including <a href=\"https:\/\/cybersecuritynews.com\/apple-released-security-updates-for-ios-ipados-macos-tvos-and-watchos\/\" target=\"_blank\" rel=\"noreferrer noopener\">iOS, iPadOS, macOS, watchOS, and tvOS<\/a>.<\/p>\n<p>The flaw has been actively exploited against older versions of iOS before iOS 17.2.<\/p>\n<p>The summary of the Vulnerabilities is given below:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVEs<\/strong><\/td>\n<td><strong>Affected Products<\/strong><\/td>\n<td><strong>Impact<\/strong><\/td>\n<td><strong>Exploit Prerequisites<\/strong><\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-24200<\/td>\n<td>iOS 18.3.1, iPadOS 18.3.1, iPadOS 17.7.5 (iPhone XS and later, iPad Pro 13-inch, iPad Pro 12.9-inch, etc.)<\/td>\n<td>Bypass USB Restricted Mode on locked devices<\/td>\n<td>Physical access to the device<\/td>\n<td>6.1 (Medium)<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-24201<\/td>\n<td>iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, visionOS 2.3.2, Safari 18.3<\/td>\n<td>Escape Web Content sandbox via malicious web content<\/td>\n<td>None<\/td>\n<td>8.1 (High)<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-24085<\/td>\n<td>iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3, visionOS 2.3<\/td>\n<td>Privilege escalation through use-after-free vulnerability in CoreMedia<\/td>\n<td>Malicious application already installed<\/td>\n<td>7.8 (High)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Mitigation Steps<\/strong><\/h2>\n<p>Apple has <a href=\"https:\/\/support.apple.com\/en-us\/122374\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> patches for all three vulnerabilities across its operating systems and devices:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>iPhones and iPads: <\/strong>Update to iOS 18.3\/iPadOS 18.3 or later.<\/li>\n<li>\n<strong>Macs: <\/strong>Install macOS Sequoia 15.3 or later.<\/li>\n<li>\n<strong>Apple Watches: <\/strong>Use watchOS 11.3 or newer.<\/li>\n<li>\n<strong>Apple TVs: <\/strong>Update to tvOS 18.3.<\/li>\n<li>\n<strong>Apple Vision Pro: <\/strong>Apply visionOS 2.3 updates.<\/li>\n<\/ul>\n<p>To update your device:<\/p>\n<ul class=\"wp-block-list\">\n<li>Navigate to Settings &gt; General &gt; Software Update.<\/li>\n<li>Enable automatic updates for future patches.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>Recommendations<\/strong><\/h2>\n<p>To further protect against exploitation:<\/p>\n<ul class=\"wp-block-list\">\n<li>Avoid installing untrusted applications or kernel extensions.<\/li>\n<li>Enable Lockdown Mode on compatible devices to reduce attack surfaces.<\/li>\n<li>Regularly monitor for software updates and apply them promptly.<\/li>\n<\/ul>\n<p>The discovery of these <a href=\"https:\/\/cybersecuritynews.com\/apple-security-update-2\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-day vulnerabilities<\/a> highlights the increasing sophistication of cyberattacks targeting Apple\u2019s ecosystem.\u00a0<\/p>\n<p>While Apple\u2019s swift response underscores its commitment to user security, users must remain vigilant by keeping their devices updated and following best practices for cybersecurity.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong><code><strong><code>Investigate Real-World Malicious Links &amp; Phishing Attacks With\u00a0<strong>Threat Intelligence Lookup<\/strong>\u00a0-\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=enrichment&amp;utm_content=plans&amp;utm_term=180325\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try for Free<\/a><\/code><\/strong><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/apple-warns-of-three-0-day-vulnerabilities\/\">Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/apple-warns-of-three-0-day-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks Apple has issued an urgent security advisory concerning three critical zero-day vulnerabilities CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085 that have been actively exploited in sophisticated attacks.\u00a0 These vulnerabilities affect a wide range of Apple devices, including iPhones, iPads, Macs, and other platforms. Users are strongly advised to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[276,129,63,416,131,517],"tags":[130],"class_list":["post-2975","post","type-post","status-publish","format-standard","hentry","category-apple","category-cyber-security","category-cyber-security-news","category-vulnerabilities","category-vulnerability","category-zero-day","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2975"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=2975"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/2975\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=2975"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=2975"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=2975"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}