A use after free issue was addressed with improved memory management. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 17.2.
https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
http://seclists.org/fulldisclosure/2025/Oct/31
http://seclists.org/fulldisclosure/2025/Oct/30
http://seclists.org/fulldisclosure/2025/Oct/23
http://seclists.org/fulldisclosure/2025/Oct/1
http://seclists.org/fulldisclosure/2025/Jun/19
http://seclists.org/fulldisclosure/2025/Jan/19
http://seclists.org/fulldisclosure/2025/Jan/15
http://seclists.org/fulldisclosure/2025/Jan/13
http://seclists.org/fulldisclosure/2025/Jan/12
http://seclists.org/fulldisclosure/2025/Apr/9
https://thehackernews.com/2025/08/apple-patches-cve-2025-43300-zero-day.html
https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html
https://www.securityweek.com/apple-patches-recent-zero-days-in-older-iphones/
https://thehackernews.com/2025/04/apple-backports-critical-fixes-for-3.html
https://www.darkreading.com/mobile-security/apple-drops-another-webkit-zero-day-bug
https://thehackernews.com/2025/03/apple-releases-patch-for-webkit-zero.html
https://thehackernews.com/2025/02/apple-patches-actively-exploited-ios.html
https://www.securityweek.com/apple-patches-first-exploited-ios-zero-day-of-2025/
https://thehackernews.com/2025/01/apple-patches-actively-exploited-zero.html