Patch SLA Tracker

CVE-2025-24165

Export this CVE's branch rows: CSV · JSON · Permalink: /cve/CVE-2025-24165

First fix
(macOS Ventura 13.7.5, macOS Sonoma 14.7.5, macOS Sequoia 15.4)
CISA KEV added
not in KEV
NVD published
(437 days after the first fix)

First fix: The release date of the earliest Apple update (including Rapid Security Responses and Background Security Improvements) whose advisory lists the CVE.

KEV date added (proxy): CISA KEV “date added” is when CISA catalogued evidence of exploitation. It is a lagging proxy: exploitation started on or before that date, usually well before.

Fix per branch

Backport gap: For one CVE and one branch: the branch's first fix date minus the earliest fix date across all branches of the same platform.

No fix listed: The branch is still maintained (it shipped a security update after the earliest fix, or its last security update is under 180 days old), but no Apple advisory lists this CVE for it as of the data date. The branch may be unaffected; Apple does not publish “not affected” statements.

Branch ended: The branch shipped no security update after the earliest fix and none in the 180 days before the data date, so it is treated as ended and not counted as missing a backport. Updates without published CVE entries do not keep a branch alive.

Fixed at branch release: The branch was first released after the earliest fix, so it is not a backport and is not counted. “Listed”: its advisory names the CVE. “Inherited”: it does not, and the fix is assumed to be in the branch from its first release.

CVE-2025-24165 timeline across branchesmacOS 27 Golden Gate fixed on 2026-09-14 (532 days after first fix, branch released later); macOS 26 Tahoe fixed on 2025-09-15 (168 days after first fix, branch released later); macOS 15 Sequoia fixed on 2025-03-31 (0 days after first fix); macOS 14 Sonoma fixed on 2025-03-31 (0 days after first fix); macOS 13 Ventura fixed on 2025-03-31 (0 days after first fix); NVD published on 2026-06-11NVD published 2026-06-11macOS 27 Golden GatemacOS 26 TahoemacOS 15 SequoiamacOS 14 SonomamacOS 13 Ventura2025-03-312026-09-14
Filled circle: first fix on that branch. Hollow circle: branch first released after the earliest fix, so it shipped with the fix (not a backport).
macOS: earliest fix
BranchStatusFirst fix on branchGap
macOS 27 Golden Gatefixed at branch release (inherited) first macOS 27 Golden Gate release–
macOS 26 Tahoefixed at branch release (inherited) first macOS 26 Tahoe release–
macOS 15 Sequoiafixed with the earliest fix macOS Sequoia 15.40 d
macOS 14 Sonomafixed with the earliest fix macOS Sonoma 14.7.50 d
macOS 13 Venturafixed with the earliest fix macOS Ventura 13.7.50 d
macOS 12 Montereybranch ended––
macOS 11 Big Surbranch ended––
macOS 10 Catalinabranch ended––

Every Apple listing

Each release whose advisory lists CVE-2025-24165, with Apple's own notes.

Apple advisories listing CVE-2025-24165
ReleaseBranchReleasedEntry addedExploited note
macOS Ventura 13.7.5macOS 13 Venturawith releaseno
macOS Sonoma 14.7.5macOS 14 Sonomawith releaseno
macOS Sequoia 15.4macOS 15 Sequoiano