logo
Home/CVEs/CVE-2025-24201/

CVE-2025-24201 - Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Project:Apple

Product:Multiple Products

Date Added:2025-03-13Due Date:2025-04-03

Vulnerability Name

Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Description

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Additional Notes

https://support.apple.com/en-us/122281

https://support.apple.com/en-us/122283

https://support.apple.com/en-us/122284

https://support.apple.com/en-us/122285

https://nvd.nist.gov/vuln/detail/CVE-2025-24201

Related News Articles

Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted AttacksApril 17, 2025

Apple fixes two zero-days exploited in targeted iPhone attacksApril 17, 2025

Apple backports zero-day patches to older iPhones and MacsApril 1, 2025

Apple Backports Critical Fixes for 3 Recent 0-Days Impacting Older iOS and macOS DevicesApril 1, 2025