CVE-2025-24091 is an Apple iOS/iPadOS vulnerability in which a malicious application can impersonate system notifications. Apple indicates that sensitive notifications now require restricted entitlements, implying the flaw stemmed from insufficient restriction or validation around which apps could present notifications resembling trusted system-originated notifications. The issue affects Apple mobile platforms prior to iOS 18.3, iPadOS 18.3, and iPadOS 17.7.3. Apple further notes that exploitation may allow an app to cause a denial-of-service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains an iOS app called EvilNotify, written in Swift, designed to interact with the iOS notification system via the notify_post API. The app allows users to add custom notification keys or use preset keys (such as 'com.apple.MobileSync.BackupAgent.RestoreStarted' and 'com.apple.springboard.toggleLockScreen') to post notifications to the system. The app is intended as a proof-of-concept for CVE-2025-24091, which relates to the abuse of certain notification keys to trigger privileged or sensitive system behaviors. The app stores user settings and notification lists in UserDefaults using specific keys. The repository structure is typical for an Xcode SwiftUI project, with the main logic in 'ContentView.swift'. No network endpoints are present; all actions are local to the device. The exploit's main capability is to allow a user to trigger system-level notifications that may be associated with privileged actions or vulnerabilities on iOS 18.0 and above.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.