An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.
History

Wed, 30 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Apr 2025 17:30:00 +0000

Type Values Removed Values Added
Description An app could impersonate system notifications. Sensitive notifications now require restricted entitlements. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.3. An app may be able to cause a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2025-04-30T17:21:08.931Z

Updated: 2025-04-30T20:22:27.632Z

Reserved: 2025-01-17T00:00:44.966Z

Link: CVE-2025-24091

cve-icon Vulnrichment

Updated: 2025-04-30T20:02:03.668Z

cve-icon NVD

Status : Received

Published: 2025-04-30T18:15:39.203

Modified: 2025-04-30T21:15:54.160

Link: CVE-2025-24091

cve-icon Redhat

No data.