Junglewise Threat Intelligence

CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

CVE-2025-24201 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2025-03-13

Technologies: Apple Safari, Apple Visionos, Apple Multiple Products, Apple watchOS, Apple macOS Sequoia. Vendors: Apple.

Executive brief

An out-of-bounds write vulnerability in WebKit allows maliciously crafted web content to bypass the Web Content sandbox. This flaw can be exploited by remote attackers to perform unauthorized actions or achieve code execution outside of the restricted environment.

Affected products

  • Apple Safari before 18.3.1
  • Apple iOS and iPadOS before 15.8.4, 16.7.11, 18.3.2, and iPadOS 17.7.6
  • Apple macOS Sequoia before 15.3.2
  • Apple visionOS before 2.3.2
  • Apple watchOS before 11.4
  • Apple WebKit

Timeline

  • 2025-03-13: disclosed
  • 2025-03-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-03-13: patched: Fixed in Safari 18.3.1, iOS 18.3.2, macOS 15.3.2, and other versions.
  • exploited: Apple reported awareness of exploitation in sophisticated attacks against targeted individuals on iOS versions prior to 17.2.

Related threats