CVE-2025-24206

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to bypass authentication policy.
References
Link Resource
https://support.apple.com/en-us/122371 Release Notes Vendor Advisory
https://support.apple.com/en-us/122372 Release Notes Vendor Advisory
https://support.apple.com/en-us/122373 Release Notes Vendor Advisory
https://support.apple.com/en-us/122374 Release Notes Vendor Advisory
https://support.apple.com/en-us/122375 Release Notes Vendor Advisory
https://support.apple.com/en-us/122377 Release Notes Vendor Advisory
https://support.apple.com/en-us/122378 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-29 03:15

Updated : 2025-10-02 01:37


NVD link : CVE-2025-24206

Mitre link : CVE-2025-24206

CVE.ORG link : CVE-2025-24206


JSON object : View

Products Affected

apple

  • visionos
  • ipados
  • iphone_os
  • tvos
  • macos
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel