PT-2025-10859 · Apple +10 · Ios +15
Gary Kwong
·
Published
2025-03-11
·
Updated
2025-08-02
·
CVE-2025-24201
10
High
Base vector | Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
visionOS versions prior to 2.3.2
iOS versions prior to 18.3.2
iPadOS versions prior to 18.3.2
macOS Sequoia versions prior to 15.3.2
Safari versions prior to 18.3.1
Description:
A critical vulnerability in the WebKit browser engine allows attackers to escape the Web Content sandbox, potentially leading to the execution of malicious code. This issue has been exploited in extremely sophisticated attacks against specific targeted individuals. The vulnerability is related to an out-of-bounds write issue when processing web content.
Recommendations:
Update to visionOS 2.3.2 or later to fix the vulnerability.
Update to iOS 18.3.2 or later to fix the vulnerability.
Update to iPadOS 18.3.2 or later to fix the vulnerability.
Update to macOS Sequoia 15.3.2 or later to fix the vulnerability.
Update to Safari 18.3.1 or later to fix the vulnerability.
Exploit
Fix
RCE
Memory Corruption
Weakness Enumeration
Related Identifiers
Affected Products
References · 910
- 🔥 https://github.com/bi-zone/CVE-2024-7965⭐ 48 🔗 10 · Exploit
- 🔥 https://github.com/XiaomingX/cve-2024-7965-poc⭐ 5 · Exploit
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8362 · Security Note
- https://osv.dev/vulnerability/SUSE-SU-2025:0974-1 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-44192 · Security Note
- https://security-tracker.debian.org/tracker/source-package/chromium · Vendor Advisory
- https://safe-surf.ru/specialists/bulletins-nkcki/711106 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24216 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-0291 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/716919 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8638 · Security Note
- https://safe-surf.ru/specialists/bulletins-nkcki/716915 · Security Note
- https://bdu.fstec.ru/vul/2024-08028 · Security Note
- https://osv.dev/vulnerability/SUSE-SU-2025:1149-1 · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31215 · Security Note