CVE-2025-24244
Description
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of process memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Processing a maliciously crafted font may lead to disclosure of process memory in Apple operating systems; fixed in iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4, and others.
CVE-2025-24244 is a memory disclosure vulnerability in Apple's font parsing engine. The issue stems from improper memory handling when processing a maliciously crafted font, potentially allowing an attacker to read process memory.
Exploitation requires the victim to process a maliciously crafted font, which could occur through visiting a web page, opening a document, or receiving a message that triggers font rendering. No special privileges are needed beyond standard user interaction.
Successful exploitation could lead to the disclosure of sensitive information from process memory, potentially including user data or cryptographic keys.
Apple addressed the issue in the following security updates: macOS Sequoia 15.4 [1], iOS 18.4 and iPadOS 18.4 [2], macOS Ventura 13.7.5 [3], and macOS Sonoma 14.7.5 [4]. Additional fixes are included in iPadOS 17.7.6, tvOS 18.4, and watchOS 11.4 as per the CVE description. Users are advised to update their devices to the latest available versions.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- support.apple.com/en-us/122371nvdVendor Advisory
- support.apple.com/en-us/122372nvdVendor Advisory
- support.apple.com/en-us/122373nvdVendor Advisory
- support.apple.com/en-us/122374nvdVendor Advisory
- support.apple.com/en-us/122375nvdVendor Advisory
- support.apple.com/en-us/122377nvdVendor Advisory
- seclists.org/fulldisclosure/2025/Apr/10nvd
- seclists.org/fulldisclosure/2025/Apr/11nvd
- seclists.org/fulldisclosure/2025/Apr/13nvd
- seclists.org/fulldisclosure/2025/Apr/4nvd
- seclists.org/fulldisclosure/2025/Apr/5nvd
- seclists.org/fulldisclosure/2025/Apr/8nvd
- seclists.org/fulldisclosure/2025/Apr/9nvd
- support.apple.com/en-us/122376nvd
News mentions
0No linked articles in our index yet.