2025-05-12
Apple Security Updates, May 2025
Apple's May 12, 2025 security updates include patches for 65 vulnerabilities. Among the notable flaws is a known exploited vulnerability in the CoreAudio framework, patched already for the most current operating systems on April 18, 2025, now patched for older systems. AppleJPEG and CoreMedia have improved input sanitization against attacks involving maliciously crafted files that could lead to app termination or corrupt process memory. CoreAudio, CoreGraphics, and ImageIO have had file-parsing flaws fixed. WebKit received patches for nine flaws that could lead to memory corruption, data exfiltration by a malicious website, process crashes, and Safari crashes. FaceTime received improved state management to fix an issue in which "Muting the microphone during a FaceTime call may not result in audio being silenced." The iOS 18.5 and iPadOS 18.5 kernel has been protected against unexpected system termination and corrupt kernel memory by improving memory handling, and against unexpected app termination by improving memory management. Multiple issues possibly leading to unexpected app termination or arbitrary code execution have also been fixed in in libexpat, an open-source XML parser. The Baseband device for iPhone 16e has received improved state management to prevent an attacker in a privileged network position from intercepting network traffic. mDNSResponder has improved checks to prevent privilege escalation. Notes has improved authentication to prevent an attacker with physical access to a device being able to access notes from the lock screen, and improved checks to prevent an attacker with physical access to a device from being able to access a deleted call recording. In addition to iOS 18.5 and iPadOS 18.5, Apple is releasing major updates for macOS Sequoia, macOS Sonoma, macOS Ventura, WatchOS, tvOS and visionOS.
Editor's Note
The updates include multiple OS versions - iOS/iPadOS 17 & 18 as well as macOS 13,14 & 15. The ISC report includes a table of which flaws affect which OS, which helps analysis, and you probably want to just roll the applicable to all your devices. Remember the Safari update is separate for macOS 13 & 14.

Lee Neely
Included in this release is an afpfs fix that is a Remote UaF in the Kernel. Patch.

Moses Frost
Read more in
Apple: About the security content of iOS 18.5 and iPadOS 18.5
SANS Internet Storm Center: Apple Updates Everything: May 2025 Edition
SecurityWeek: Apple Patches Major Security Flaws in iOS, macOS Platforms