CERT-in Warns Of High-Risk Security Flaws In Apple Products

CERT-in has given the vulnerabilities in Apple devices a severity rating of “High”.

Advertisement
Written by Nithya P Nair, Edited by Siddharth Suvarna | Updated: 30 January 2025 15:34 IST
Highlights
  • CERT-in has found multiple security flaws in Apple operating systems
  • The advisory affects a wide range of Apple products
  • The advisory was issued on January 28

The vulnerabilities affects Apple devices running older versions of iOS, iPadOS, and macOS

Photo Credit: Apple

Indian Computer Emergency Response Team (CERT-In) has issued a warning to Apple users concerning multiple vulnerabilities found in iPad, Mac and other models. The advisory was issued this week after the government agency discovered many security flaws in the operating system that powers Apple's tablets, iPhone models and laptops among others. These vulnerabilities, if exploited, could allow attackers to access sensitive information from the systems. 

CERT-in Issues Advisory Related to Vulnerabilities in Apple Devices

In an advisory dated January 28, CERT-In states that multiple vulnerabilities have been reported in Apple products. This could allow the attacker to access sensitive information, execute arbitrary code, bypass security restrictions, cause denial of service (DoS) conditions, bypass authentication, gain elevated privileges, data manipulation and perform spoofing attacks on the targeted system.

CERT-In's advisory outlines the affected Apple products —  Apple macOS Sequoia versions before 15.3, macOS Sonoma versions before 14.7.3, macOS Ventura versions before 13.7.3, and iPadOS versions before 17.7.4.

Advertisement

The iOS, tvOS and iPadOS versions prior to 18.3, visionOS versions prior to 2.3, Safari Versions before 18.3 and watchOS versions prior to 11.3 are also said to be affected by these vulnerabilities. The vulnerabilities are rated as "high risk".

The government agency states that the identified vulnerabilities stem from null pointer dereference, type confusion error, use after free error, out-of-bounds read, out-of-bounds write, handling of files, parsing a file, input validation, user-sensitive data, and more. The nodal agency notes that one of the reported vulnerabilities — CVE-2025-24085 — is a critical one and is actively exploited. It affects Apple devices running older versions of iOS, iPadOS, and macOS.

The advisory recommends users update their Apple devices to the latest versions of software to mitigate the risks. The government advisory comes a few days after Apple released its latest software update for iPhone, iPad and Mac users.

Advertisement

 

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Jan 12 - Jan 18): Taskaree, 120 Bahadur, and More
  2. Here's How Much the Vivo X200T Could Cost in India: See Expected Specs
  3. Redmi Buds 8 Lite Launched With ANC, Up to 36 Hours Total Battery Life
  4. Amazon Great Republic Day Sale: Top Deals on Premium Smartphones
  1. Hypothetical ‘Dark Stars’ Could Rewrite Early Cosmic History, Research Suggests
  2. Honor Magic 8 Pro Air Key Features Confirmed; Company Teases External Lens for Honor Magic 8 RSR Porsche Design
  3. Lava Blaze Duo 3 India Launch Date Announced; Colour Options Teased Ahead of Debut
  4. Resident Evil Requiem Gets New Leon Gameplay at Resident Evil Showcase
  5. After ChatGPT Translate, Google Releases Multiple Open-Source Translation Models
  6. Realme Buds Clip India Launch Timeline Confirmed: Expected Specifications, Features
  7. NASA's James Webb Space Telescope Might Have Spotted Hidden Supermassive Black Holes
  8. Tere Ishk Mein Reportedly Streams on OTT Soon: All You Need to Know About Dhanush and Kriti Sanon-Starrer
  9. Amazon Great Republic Day Sale: Top Laptop Deals Under Rs. 40,000
  10. OnePlus 15T Launch Timeline, Chipset Details Leaked: Expected Specifications, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.