ZeroHour
CyberScooppublished ()ingested @gregotto

Apple discloses zero-day vulnerability, releases emergency patches

criticalExploit / PoCimportance 60CVE-2025-24201

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24201
WebKit Out-of-Bounds Write Sandbox Escape in Apple iOS, Safari, and macOS

CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, the web rendering engine used across Apple's platforms, which Apple addressed with improved bounds checks. It is triggered by processing maliciously crafted web content, meaning a victim only has to load attacker-controlled web content in Safari or in any app that renders web content. A successful attacker can break out of the Web Content sandbox and perform unauthorized actions, an impact CISA scores at CVSS 10.0 (critical, scope-changing). Affected users include anyone running vulnerable versions of iOS, iPadOS, macOS Sequoia, Safari, visionOS, or watchOS; Debian Linux is also listed in the CPE data because Debian ships WebKit in its webkit packages. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2 (this patch is a supplementary fix for that previously blocked attack, extended to older branches), and the CVE was added to CISA's KEV catalog on 2025-03-13.

Do: Apply the vendor fixes immediately: Safari 18.3.1; iOS/iPadOS 18.3.2 (or 17.7.6, 16.7.11, or 15.8.4 on devices that cannot run the newest release); macOS Sequoia 15.3.2; visionOS 2.3.2; watchOS 11.4; and updated Debian webkit packages per Debian advisories. Because the CVE is in CISA's KEV catalog (added 2025-03-13), US federal agencies must patch per BOD 22-01, and all defenders should prioritize fleets with high-risk or frequently targeted users. Given the 'extremely sophisticated' targeted exploitation against individuals on iOS before 17.2, check whether targeted or high-value users' devices show indicators of compromise and ensure they are not left on older branches.

10.04% KEV
  • Apple Safari Versions prior to 18.3.1; fixed in Safari 18.3.1
  • Apple iPhone OS (iOS) iOS 15.x, 16.x and 18.x prior to the fixes; fixed in iOS 15.8.4, iOS 16.7.11, and iOS 18.3.2 (the referenced in-the-wild attacks targeted iOS versions before 17
  • Apple iPadOS iPadOS 15.x, 16.x, 17.x and 18.x prior to the fixes; fixed in iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.3.2
  • +4 more
mass≈2 billion+ active Apple devices (iPhone, iPad, Mac, Apple Watch and Vision Pro all ship the affected WebKit; Apple publicly reports an active installed base…
Full article502 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Listen to this article

0:00

Learn more.

The Apple logo is seen on a window of the company's store in Bangkok on March 5, 2021. (Photo by Mladen ANTONOV / AFP) (Photo by MLADEN ANTONOV/AFP via Getty Images)

Apple released emergency software patches Tuesday that address a newly identified zero-day vulnerability in the company’s WebKit web browser engine. 

Tracked as CVE-2025-24201, an attacker can potentially escape the constraints of Webkit’s Web Content sandbox, potentially leading to unauthorized actions. The sandbox is a security feature that isolates untrusted web content in order to prevent malicious code from accessing critical parts of the system.

Apple categorized the attack as “extremely sophisticated,” saying it was used in attacks on “specific targeted individuals” prior to the iOS 17.2 update integral to Apple’s Safari browser and other applications across macOS and iOS. 

The vulnerability marks the third zero-day Apple has tackled this year, with previous issues being identified and patched in January and February. The patches resolve the issue across various Apple operating systems, including iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, visionOS 2.3.2, and Safari 18.3.1.

Notably, Apple did not disclose if its own researchers or others outside of the company discovered the vulnerability, maintaining its policy of withholding specific exploitation details to prevent aiding malicious actors. The company did the same with the January zero-day, which was linked to its Core Media framework. This earlier flaw reportedly showcased use-after-free vulnerabilities, leading to unauthorized system access and prompting further vigilance.

Apple did name the researcher behind February’s zero-day announcement, which was discovered by Bill Marczak of The Citizen Lab. That vulnerability, which disabled USB Restricted Mode on a locked Apple device, drew attention to nation-state surveillance capabilities. 

More information about the patches are available on Apple’s website

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/apple-zero-day-patch-march-2025-cve-2025-24201/