CVE-2025-24091

A

n app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

12 May 2025, 19:43

Type Values Removed Values Added
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/121838 - () https://support.apple.com/en-us/121838 - Vendor Advisory
References () https://support.apple.com/en-us/122066 - () https://support.apple.com/en-us/122066 - Vendor Advisory
First Time Apple iphone Os
Apple
Apple ipados

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Una aplicación podría suplantar las notificaciones del sistema. Las notificaciones sensibles ahora requieren permisos restringidos. Este problema se solucionó en iOS 18.3, iPadOS 18.3 y iPadOS 17.7.3. Una aplicación podría causar una denegación de servicio.

30 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5

30 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-30 18:15

Updated : 2025-05-12 19:43


NVD link : CVE-2025-24091

Mitre link : CVE-2025-24091

CVE.ORG link : CVE-2025-24091


JSON object : View

Products Affected
CWE
CWE-290

Authentication Bypass by Spoofing