ZeroHour

CVE-2025-24201

KEVmass

WebKit Out-of-Bounds Write Sandbox Escape in Apple iOS, Safari, and macOS

CISA: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

CVSS 3.1
10.0 critical
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, the web rendering engine used across Apple's platforms, which Apple addressed with improved bounds checks. It is triggered by processing maliciously crafted web content, meaning a victim only has to load attacker-controlled web content in Safari or in any app that renders web content. A successful attacker can break out of the Web Content sandbox and perform unauthorized actions, an impact CISA scores at CVSS 10.0 (critical, scope-changing). Affected users include anyone running vulnerable versions of iOS, iPadOS, macOS Sequoia, Safari, visionOS, or watchOS; Debian Linux is also listed in the CPE data because Debian ships WebKit in its webkit packages. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2 (this patch is a supplementary fix for that previously blocked attack, extended to older branches), and the CVE was added to CISA's KEV catalog on 2025-03-13.

What to do: Apply the vendor fixes immediately: Safari 18.3.1; iOS/iPadOS 18.3.2 (or 17.7.6, 16.7.11, or 15.8.4 on devices that cannot run the newest release); macOS Sequoia 15.3.2; visionOS 2.3.2; watchOS 11.4; and updated Debian webkit packages per Debian advisories. Because the CVE is in CISA's KEV catalog (added 2025-03-13), US federal agencies must patch per BOD 22-01, and all defenders should prioritize fleets with high-risk or frequently targeted users. Given the 'extremely sophisticated' targeted exploitation against individuals on iOS before 17.2, check whether targeted or high-value users' devices show indicators of compromise and ensure they are not left on older branches.

Affected
Apple SafariVersions prior to 18.3.1; fixed in Safari 18.3.1
Apple iPhone OS (iOS)iOS 15.x, 16.x and 18.x prior to the fixes; fixed in iOS 15.8.4, iOS 16.7.11, and iOS 18.3.2 (the referenced in-the-wild attacks targeted iOS versions before 17
Apple iPadOSiPadOS 15.x, 16.x, 17.x and 18.x prior to the fixes; fixed in iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.3.2
Apple macOS SequoiaVersions prior to 15.3.2; fixed in macOS Sequoia 15.3.2
Apple visionOSVersions prior to 2.3.2; fixed in visionOS 2.3.2
Apple watchOSVersions prior to 11.4; fixed in watchOS 11.4
Debian Linux (WebKit)Listed as affected in CISA CPE data; no specific Debian version ranges were provided in the source data
Estimated exposure
mass≈2 billion+ active Apple devices (iPhone, iPad, Mac, Apple Watch and Vision Pro all ship the affected WebKit; Apple publicly reports an active installed base… — Apple's WebKit is present on essentially every active iPhone, iPad, Mac, Apple Watch and Vision Pro, so the affected install base is at least Apple's publicly disclosed 2.2 billion active devices (Debian's webkit2gtk deployments add a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
appledebian
Products
safari, macos, visionos, watchos, ipados, iphone os, debian linux
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news