
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24124 is a vulnerability discovered in Apple's CoreMedia component affecting multiple Apple operating systems including iOS, iPadOS, macOS, watchOS, tvOS and visionOS. The vulnerability was reported by Pwn2car & Rotiple (HyeongSeok Jang) working with Trend Micro Zero Day Initiative and was patched in January 2025 (Apple Support).
The vulnerability is related to file parsing in the CoreMedia component. According to Apple's security advisory, the issue was addressed with improved checks. When exploited, the vulnerability could lead to unexpected app termination (Apple Support).
The vulnerability affects multiple Apple operating systems and devices. When successfully exploited, it could cause application termination, potentially disrupting user operations (Apple Support).
Apple has addressed this vulnerability in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, visionOS 2.3, watchOS 11.3, and tvOS 18.3. Users are advised to update their devices to the latest available versions to receive the security fixes (Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."