CVE-2025-24201

Name
CVE-2025-24201
Description
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, watchOS 11.4, iPadOS 17.7.6, iOS 16.7.11 and iPadOS 16.7.11, iOS 15.8.4 and iPadOS 15.8.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
product-security@apple.com https://support.apple.com/en-us/122281
product-security@apple.com https://support.apple.com/en-us/122283
product-security@apple.com https://support.apple.com/en-us/122284
product-security@apple.com https://support.apple.com/en-us/122285
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Mar/2
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Mar/3
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Mar/4
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Mar/5
https://support.apple.com/en-us/122376
https://support.apple.com/en-us/122372
https://support.apple.com/en-us/122346
https://support.apple.com/en-us/122345
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Apr/16
134c704f-9b21-4f2e-91b3-4a467353bcc0 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24201
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Oct/31
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Oct/1
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Jun/19
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/06/msg00016.html
af854a3a-2127-422b-91ae-364da2661108 http://seclists.org/fulldisclosure/2025/Apr/7
af854a3a-2127-422b-91ae-364da2661108 https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
af854a3a-2127-422b-91ae-364da2661108 https://github.com/cisagov/vulnrichment/issues/194

Match rules

CPE URI Source package Min version Max version
ios-and-ipados == unspecified == None
macos == unspecified == None
visionos == unspecified == None
safari == unspecified == None
watchos == unspecified == None
ipados == unspecified == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
qt6-qtwebengine edge-community 6.8.2-r3 Bart Ribbers <bribbers@disroot.org> fixed
qt6-qtwebengine 3.22-community 6.8.2-r3 None fixed
qt5-qtwebengine edge-community 5.15.17-r10 Bart Ribbers <bribbers@disroot.org> fixed
qt5-qtwebengine 3.22-community 5.15.17-r10 Bart Ribbers <bribbers@disroot.org> fixed
qt5-qtwebengine 3.21-community 5.15.17-r7 Bart Ribbers <bribbers@disroot.org> fixed