CVE Vulnerabilities

CVE-2025-24210

Operator Precedence Logic Error

Published: Mar 31, 2025 | Modified: Nov 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A logic error was addressed with improved error handling. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Parsing an image may lead to disclosure of user information.

Weakness

The product uses an expression in which operator precedence causes incorrect logic to be used.

Affected Software

NameVendorStart VersionEnd Version
IpadosApple*17.7.6 (excluding)
IpadosApple18.0 (including)18.4 (excluding)
Iphone_osApple*18.4 (excluding)
MacosApple13.0 (including)13.7.5 (excluding)
MacosApple14.0 (including)14.7.5 (excluding)
MacosApple15.0 (including)15.4 (excluding)
TvosApple*18.4 (excluding)
VisionosApple*2.4 (excluding)

Potential Mitigations

References