ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

iOS 18.3.2 Patches Actively Exploited WebKit Vulnerability

criticalVulnerability exploited in the wildimportance 60CVE-2025-24201

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24201
WebKit Out-of-Bounds Write Sandbox Escape in Apple iOS, Safari, and macOS

CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, the web rendering engine used across Apple's platforms, which Apple addressed with improved bounds checks. It is triggered by processing maliciously crafted web content, meaning a victim only has to load attacker-controlled web content in Safari or in any app that renders web content. A successful attacker can break out of the Web Content sandbox and perform unauthorized actions, an impact CISA scores at CVSS 10.0 (critical, scope-changing). Affected users include anyone running vulnerable versions of iOS, iPadOS, macOS Sequoia, Safari, visionOS, or watchOS; Debian Linux is also listed in the CPE data because Debian ships WebKit in its webkit packages. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2 (this patch is a supplementary fix for that previously blocked attack, extended to older branches), and the CVE was added to CISA's KEV catalog on 2025-03-13.

Do: Apply the vendor fixes immediately: Safari 18.3.1; iOS/iPadOS 18.3.2 (or 17.7.6, 16.7.11, or 15.8.4 on devices that cannot run the newest release); macOS Sequoia 15.3.2; visionOS 2.3.2; watchOS 11.4; and updated Debian webkit packages per Debian advisories. Because the CVE is in CISA's KEV catalog (added 2025-03-13), US federal agencies must patch per BOD 22-01, and all defenders should prioritize fleets with high-risk or frequently targeted users. Given the 'extremely sophisticated' targeted exploitation against individuals on iOS before 17.2, check whether targeted or high-value users' devices show indicators of compromise and ensure they are not left on older branches.

10.04% KEV
  • Apple Safari Versions prior to 18.3.1; fixed in Safari 18.3.1
  • Apple iPhone OS (iOS) iOS 15.x, 16.x and 18.x prior to the fixes; fixed in iOS 15.8.4, iOS 16.7.11, and iOS 18.3.2 (the referenced in-the-wild attacks targeted iOS versions before 17
  • Apple iPadOS iPadOS 15.x, 16.x, 17.x and 18.x prior to the fixes; fixed in iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.3.2
  • +4 more
mass≈2 billion+ active Apple devices (iPhone, iPad, Mac, Apple Watch and Vision Pro all ship the affected WebKit; Apple publicly reports an active installed base…
Full article296 words · extracted from infosecurity-magazine.com · click to collapse

Apple has released iOS 18.3.2 and iPadOS 18.3.2 to fix a critical WebKit vulnerability that has been actively exploited by cybercriminals. 

The flaw (CVE-2025-24201) allowed maliciously crafted web content to break out of the Web Content sandbox, posing a serious security risk. Initially believed to have been patched in iOS 17.2, Apple has now issued a supplementary fix to fully address the issue.

The tech giant has also confirmed that this vulnerability was used in a highly sophisticated attack targeting specific individuals before iOS 17.2.

Read more on attacks targeting Apple devices: New LightSpy Spyware Targets iOS with Enhanced Capabilities

“It’s essential that all iOS users update to iOS 18.3.2, as the fix addresses a flaw that has been actively exploited by cybercriminals,” warned Adam Boynton, senior security strategy manager EMEIA at Jamf.

“Cybercriminals will attempt to compromise devices that have not been updated. Therefore, we strongly recommend that users install iOS 18.3.2 immediately. Keeping devices up to date with the latest patches is one of the most effective ways to safeguard against attackers.”

Since WebKit is the framework that powers Safari and other web-based content on iOS, vulnerabilities can have widespread consequences.

“Vulnerabilities in WebKit should be patched quickly,” Boynton explained. “In this particular flaw, attackers were able to use maliciously crafted web content to escape the iOS Web Content sandbox. Breaking out of a sandbox allows an attacker to access data in other parts of the operating system.”

The update is available for iPhone XS and later, multiple iPad Pro models, iPad Air (3rd generation and later) and iPad mini (5th generation and later). Users are urged to update their devices by going to Settings > General > Software Update to ensure protection against potential cyber-threats.

Image credit: nikkimeel / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/ios-1832-patches-exploited-webkit/