• ISC Stormcast For Tuesday, May 13th, 2025 https://isc.sans.edu/podcastdetail/9448, (Tue, May 13th) SANS Internet Storm Center, InfoCON: green
    • NSO Group’s Legal Loss May Do Little to Curtail Spyware darkreadingRobert Lemos, Contributing Writer
    • Apple Updates Everything: May 2025 Edition, (Mon, May 12th) SANS Internet Storm Center, InfoCON: green
    • Attackers Lace Fake Generative AI Tools With ‘Noodlophile’ Malware darkreadingAlexander Culafi, Senior News Writer, Dark Reading
    • 4 Hackers Arrested After Millions Made in Global Botnet Business darkreadingKristina Beek, Associate Editor, Dark Reading
    • The Beginner’s Guide to Using AI: 5 Easy Ways to Get Started (Without Accidentally Summoning Skynet)
      by Tech Jacks
      March 29, 2025
    • Tips and Tricks to Enhance Your Incident Response Procedures
      by Tech Jacks
      March 17, 2025
    • Building a Security Roadmap for Your Company: Strategic Precision for Modern Enterprises 
      by Tech Jacks
      March 10, 2025
    • The Power of Policy: How Creating Strong Standard Operating Procedures Expedites Security Initiatives
      by Tech Jacks
      March 6, 2025
    • Building a Future-Proof SOC: Strategies for CISOs and Infosec Leaders 
      by Tech Jacks
      March 3, 2025
    • Security Gate Keeping – Annoying – Unhelpful
      by Tech Jacks
      November 13, 2024

  • Home
  • Blog & Observations
  • Articles
    • Guest Author
      • Peter Ramadan
        • SOC IT to ME
        • The Power of Policy
        • CISO Elite
  • In The News
  • Podcast & Vlogs
    • Podcast Videos
    • Security Unfiltered Podcast Information
  • Training & Videos
    • AI
      • AI Governance
    • Cloud
      • AWS
      • Azure
      • Google Cloud
    • Networking
    • Scripting
    • Security
      • Application Security
      • Cloud Security
      • Incident Response
      • Pentesting Information
      • Risk Management
      • Security Policy
    • Servers
    • Microsoft SCCM
    • ISC2
  • Services

Apple Updates Everything: May 2025 Edition, (Mon, May 12th) SANS Internet Storm Center, InfoCON: green

May 12, 2025

Apple released its expected update for all its operating systems. The update, in addition to providing new features, patches 65 different vulnerabilities. Many of these vulnerabilities affect multiple operating systems within the Apple ecosystem. 

Apple released its expected update for all its operating systems. The update, in addition to providing new features, patches 65 different vulnerabilities. Many of these vulnerabilities affect multiple operating systems within the Apple ecosystem.

Of note is CVE-2025-31200. This vulnerability is already exploited in “targeted attacks”. Apple released patches for this vulnerability in mid-April for its current operating Systems (iOS 18, macOS 15, tvOS 18, and visionOS 2). This update includes patches for older versions of macOS and iPadOS/iOS.

 

iOS 18.5 and iPadOS 18.5 iPadOS 17.7.7 macOS Sequoia 15.5 macOS Sonoma 14.7.6 macOS Ventura 13.7.6 watchOS 11.5 tvOS 18.5 visionOS 2.5
CVE-2025-24097: An app may be able to read arbitrary file metadata.
Affects AirDrop
  x            
CVE-2025-24111: An app may be able to cause unexpected system termination.
Affects Display
  x            
CVE-2025-24142: An app may be able to access sensitive user data.
Affects Notification Center
    x x x      
CVE-2025-24144: An app may be able to leak sensitive kernel state.
Affects Kernel
  x   x x      
CVE-2025-24155: An app may be able to disclose kernel memory.
Affects WebContentFilter
      x x      
CVE-2025-24213: A type confusion issue could lead to memory corruption.
Affects WebKit
x x x     x x x
CVE-2025-24220: An app may be able to read a persistent device identifier.
Affects Sandbox Profiles
  x            
CVE-2025-24222: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects BOM
    x          
CVE-2025-24223: Processing maliciously crafted web content may lead to memory corruption.
Affects WebKit
    x          
CVE-2025-24225: Processing an email may lead to user interface spoofing.
Affects Mail Addressing
x x            
CVE-2025-24258: An app may be able to gain root privileges.
Affects DiskArbitration
      x x      
CVE-2025-24259: An app may be able to retrieve Safari bookmarks without an entitlement check.
Affects Parental Controls
  x            
CVE-2025-24274: A malicious app may be able to gain root privileges.
Affects Mobile Device Service
    x x x      
CVE-2025-30440: An app may be able to bypass ASLR.
Affects Libinfo
    x x x      
CVE-2025-30442: An app may be able to gain elevated privileges.
Affects SoftwareUpdate
      x x      
CVE-2025-30443: An app may be able to access user-sensitive data.
Affects Found in Apps
    x          
CVE-2025-30448: An attacker may be able to turn on sharing of an iCloud folder without authentication.
Affects iCloud Document Sharing
x x   x x     x
CVE-2025-30453: A malicious app may be able to gain root privileges.
Affects DiskArbitration
      x x      
CVE-2025-31196: Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents.
Affects CoreGraphics
  x   x x      
CVE-2025-31200: Processing an audio stream in a maliciously crafted media file may result in code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS released before iOS 18.4.1..
Affects CoreAudio
          x    
CVE-2025-31204: Processing maliciously crafted web content may lead to memory corruption.
Affects WebKit
x         x x x
CVE-2025-31205: A malicious website may exfiltrate data cross-origin.
Affects WebKit
x   x     x x x
CVE-2025-31206: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affects WebKit
x x x     x x x
CVE-2025-31207: An app may be able to enumerate a user’s installed apps.
Affects FrontBoard
x              
CVE-2025-31208: Parsing a file may lead to an unexpected app termination.
Affects CoreAudio
x x x x x x x x
CVE-2025-31209: Parsing a file may lead to disclosure of user information.
Affects CoreGraphics
x x x x x x x x
CVE-2025-31210: Processing web content may lead to a denial-of-service.
Affects FaceTime
x x            
CVE-2025-31212: An app may be able to access sensitive user data.
Affects Core Bluetooth
x   x     x x x
CVE-2025-31213: An app may be able to access associated usernames and websites in a user’s iCloud Keychain.
Affects Security
  x x x x      
CVE-2025-31214: An attacker in a privileged network position may be able to intercept network traffic.
Affects Baseband
x              
CVE-2025-31215: Processing maliciously crafted web content may lead to an unexpected process crash.
Affects WebKit
x x x     x x x
CVE-2025-31217: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affects WebKit
x x x     x x x
CVE-2025-31218: An app may be able to observe the hostnames of new network connections.
Affects NetworkExtension
    x          
CVE-2025-31219: An attacker may be able to cause unexpected system termination or corrupt kernel memory.
Affects Kernel
x x x x x x x x
CVE-2025-31220: A malicious app may be able to read sensitive location information.
Affects Weather
  x x x x      
CVE-2025-31221: A remote attacker may be able to leak memory.
Affects Security
x x x x x x x x
CVE-2025-31222: A user may be able to elevate privileges.
Affects mDNSResponder
x   x x x x x x
CVE-2025-31224: An app may be able to bypass certain Privacy preferences.
Affects Sandbox
    x x x      
CVE-2025-31225: Call history from deleted apps may still appear in spotlight search results.
Affects Call History
x              
CVE-2025-31226: Processing a maliciously crafted image may lead to a denial-of-service.
Affects ImageIO
x x x     x x x
CVE-2025-31227: An attacker with physical access to a device may be able to access a deleted call recording.
Affects Notes
x              
CVE-2025-31228: An attacker with physical access to a device may be able to access notes from the lock screen.
Affects Notes
x x            
CVE-2025-31232: A sandboxed app may be able to access sensitive user data.
Affects Installer
    x x x      
CVE-2025-31233: Processing a maliciously crafted video file may lead to unexpected app termination or corrupt process memory.
Affects CoreMedia
x x x x x x x x
CVE-2025-31234: An attacker may be able to cause unexpected system termination or corrupt kernel memory.
Affects Pro Res
x   x       x x
CVE-2025-31235: An app may be able to cause unexpected system termination.
Affects Audio
  x x x x      
CVE-2025-31236: An app may be able to access sensitive user data.
Affects Finder
    x          
CVE-2025-31237: Mounting a maliciously crafted AFP network share may lead to system termination.
Affects afpfs
    x x x      
CVE-2025-31238: Processing maliciously crafted web content may lead to memory corruption.
Affects WebKit
x   x     x x x
CVE-2025-31239: Parsing a file may lead to an unexpected app termination.
Affects CoreMedia
x x x x x x x x
CVE-2025-31241: A remote attacker may cause an unexpected app termination.
Affects Kernel
x x x x x x x x
CVE-2025-31242: An app may be able to access sensitive user data.
Affects StoreKit
  x x x x      
CVE-2025-31244: An app may be able to break out of its sandbox.
Affects quarantine
    x          
CVE-2025-31245: An app may be able to cause unexpected system termination.
Affects Pro Res
x x x x x   x x
CVE-2025-31246: Connecting to a malicious AFP server may corrupt kernel memory.
Affects afpfs
    x x        
CVE-2025-31247: An attacker may gain access to protected parts of the file system.
Affects SharedFileList
    x x x      
CVE-2025-31249: An app may be able to access sensitive user data.
Affects Sandbox
    x          
CVE-2025-31250: An app may be able to access sensitive user data.
Affects TCC
    x          
CVE-2025-31251: Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory.
Affects AppleJPEG
x x x x x x x x
CVE-2025-31253: Muting the microphone during a FaceTime call may not result in audio being silenced.
Affects FaceTime
x              
CVE-2025-31256: Hot corner may unexpectedly reveal a user?s deleted notes.
Affects Notes
    x          
CVE-2025-31257: Processing maliciously crafted web content may lead to an unexpected Safari crash.
Affects WebKit
x   x     x x x
CVE-2025-31258: An app may be able to break out of its sandbox.
Affects RemoteViewServices
    x          
CVE-2025-31259: An app may be able to gain elevated privileges.
Affects SoftwareUpdate
    x          
CVE-2025-31260: An app may be able to access sensitive user data.
Affects Apple Intelligence Reports
    x          

—
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. 

​Read More

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to email a link to a friend (Opens in new window) Email

Like this:

Like Loading...
Share

In The News

Tech Jacks
Derrick Jackson is a IT Security Professional with over 10 years of experience in Cybersecurity, Risk, & Compliance and over 15 Years of Experience in Enterprise Information Technology

Leave A Reply


Leave a Reply Cancel reply

You must be logged in to post a comment.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Blog

    • Security Gate Keeping - Annoying - Unhelpful
      November 13, 2024
    • 15 Years on LinkedIn: An Authentic Reflection(or a Beauty...
      October 24, 2024
    • Podcast & Cloud Security Governance
      February 24, 2021
    • The Journey Continues - Moving through 2021
      January 5, 2021
    • CISSP Journey
      February 22, 2019




  • About TechJacks
  • Privacy Policy
  • Gaming Kaiju
© Copyright Tech Jacks Solutions 2025

%d