CVE-2025-24139

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Ventura 13.7.5. Parsing a maliciously crafted file may lead to an unexpected app termination.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

02 Apr 2026, 19:19

Type Values Removed Values Added
References
  • () https://support.apple.com/en-us/122375 -
Summary (en) The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a maliciously crafted file may lead to an unexpected app termination. (en) The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, macOS Ventura 13.7.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Apr/10 -
  • () http://seclists.org/fulldisclosure/2025/Jan/15 -
  • () http://seclists.org/fulldisclosure/2025/Jan/16 -
  • () http://seclists.org/fulldisclosure/2025/Jan/17 -

24 Mar 2025, 18:15

Type Values Removed Values Added
CWE CWE-787

03 Mar 2025, 22:45

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
First Time Apple
Apple macos
References () https://support.apple.com/en-us/122068 - () https://support.apple.com/en-us/122068 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122069 - () https://support.apple.com/en-us/122069 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122070 - () https://support.apple.com/en-us/122070 - Release Notes, Vendor Advisory

18 Feb 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown
CWE CWE-770

28 Jan 2025, 16:15

Type Values Removed Values Added
CWE CWE-770
Summary
  • (es) El problema se solucionó con comprobaciones mejoradas. Este problema se solucionó en macOS Ventura 13.7.3, macOS Sequoia 15.3 y macOS Sonoma 14.7.3. Analizar un archivo manipulado malintencionado puede provocar la finalización inesperada de una aplicación.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2026-04-02 19:19


NVD link : CVE-2025-24139

Mitre link : CVE-2025-24139

CVE.ORG link : CVE-2025-24139


JSON object : View

Products Affected

apple

  • macos
CWE
NVD-CWE-noinfo CWE-787

Out-of-bounds Write