Severity
High
Analysis Summary
CVE-2025-24177 CVSS:7.5
Apple macOS Sequoia is vulnerable to a denial of service, caused by a NULL pointer dereference in the AirPlay component.
CVE-2025-24169 CVSS:6.6
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.3, Safari 18.3. A malicious app may be able to bypass browser extension authentication.
Impact
- Denial of Service
- Security Bypass
Indicators of Compromise
CVE
CVE-2025-24177
CVE-2025-24169
Affected Vendors
- Apple
Affected Products
- Apple Safari - 18.2
- Apple macOS Sequoia - 15.2
Remediation
Upgrade to the latest version, available from the Apple Website.