cbcvebase.
CVE-2025-24085
published 2025-01-27

CVE-2025-24085: A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS…

PriorityP192critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-02-19
Exploited in the wild
EPSS
18.67%
96.9th percentile
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.6, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3, watchOS 11.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_18.3_and_ipados
appleios_and_ipados< 18.318.3
appleipados< 17.7.617.7.6
appleipados
appleipados>= 18.0 < 18.318.3
appleiphone_os< 18.318.3
applemacos< 13.7.513.7.5
applemacos< 14.7.514.7.5
applemacos< 15.315.3
applemacos>= 13.0 < 13.7.513.7.5
applemacos>= 14.0 < 14.7.514.7.5
applemacos>= 15.0 < 15.315.3
applemacos_sequoia
applemacos_sonoma
applemacos_ventura
appletvos< 18.318.3
appletvos
applevisionos< 2.32.3
applevisionos
applewatchos< 11.311.3
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

path/Library/LaunchDaemons/com.apple.securemonitor.plist
path/tmp/.macroot_payload.sh
path/tmp/.rootbash
path/tmp/.rootlog
path/Library/LaunchDaemons/com.apple.backdoor.plist
commandsudo launchctl load -w /Library/LaunchDaemons/com.apple.securemonitor.plist
command/tmp/.rootbash -p
commandsysadminctl -addUser pentest -password macOS123! -admin
  • CVE-2025-24085 is a use-after-free in CoreMedia (Apple) actively exploited against iOS versions before 17.2 via a malicious application to elevate privileges. Monitor for privilege escalation from sandboxed app processes.
  • Alert on creation of hidden files under /tmp/ with names beginning with a dot (e.g., .rootbash, .macroot_payload.sh) combined with setuid bit (chmod +s) being applied, as this is a post-exploitation persistence pattern for this CVE's PoC.
  • Detect use of sysadminctl to add new admin users from non-interactive or scripted contexts, which may indicate post-exploitation persistence following privilege escalation.
  • ·The Exploit-DB PoC (exploit 52316) is attributed to a third-party researcher and targets macOS via LaunchDaemon hijacking. The original in-the-wild exploitation vector against iOS before 17.2 is not publicly detailed by Apple; the PoC may not reflect the actual exploitation technique used in targeted attacks.
  • ·Apple has not shared further details on how the flaw was exploited in the wild; detection based on the PoC should be treated as covering one possible exploitation path, not confirmed attacker TTPs.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
cisa10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.