Apple has released security updates for older device models, addressing three actively exploited vulnerabilities. These critical patches extend protection to users who haven’t upgraded to the latest hardware or operating systems.
## Vulnerabilities Addressed
– **CVE-2025-24085** (CVSS 7.3): A use-after-free bug in Core Media that allows installed malicious applications to elevate privileges
– **CVE-2025-24200** (CVSS 4.6): An authorization flaw in Accessibility that could disable USB Restricted Mode on locked devices during physical attacks
– **CVE-2025-24201** (CVSS 8.8): An out-of-bounds write issue in WebKit enabling attackers to escape the Web Content sandbox via malicious web content
## Update Availability
The vulnerabilities have been patched in specific OS versions:
– **CVE-2025-24085**: Fixed in macOS Sonoma 14.7.5, macOS Ventura 13.7.5, and iPadOS 17.7.6
– **CVE-2025-24200** and **CVE-2025-24201**: Fixed in iOS 15.8.4, iPadOS 15.8.4, iOS 16.7.11, and iPadOS 16.7.11
## Supported Devices
– **iOS/iPadOS 15.8.4**: iPhone 6s, iPhone 7, iPhone SE (1st gen), iPad Air 2, iPad mini (4th gen), iPod touch (7th gen)
– **iOS/iPadOS 16.7.11**: iPhone 8, iPhone 8 Plus, iPhone X, iPad (5th gen), iPad Pro 9.7-inch, iPad Pro 12.9-inch (1st gen)
– **iPadOS 17.7.6**: iPad Pro 12.9-inch (2nd gen), iPad Pro 10.5-inch, iPad (6th gen)
This security update coincides with Apple’s release of iOS/iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, and Safari 18.4, which collectively fix hundreds of vulnerabilities. While the newly disclosed issues aren’t currently being exploited, users are strongly advised to update their devices immediately.
