Executive brief
An out-of-bounds write vulnerability in WebKit allows maliciously crafted web content to bypass the Web Content sandbox. This flaw can be exploited by remote attackers to perform unauthorized actions or achieve code execution outside of the restricted environment.
Affected products
- Apple Safari before 18.3.1
- Apple iOS and iPadOS before 15.8.4, 16.7.11, 18.3.2, and iPadOS 17.7.6
- Apple macOS Sequoia before 15.3.2
- Apple visionOS before 2.3.2
- Apple watchOS before 11.4
- Apple WebKit
Timeline
- 2025-03-13: disclosed
- 2025-03-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-03-13: patched: Fixed in Safari 18.3.1, iOS 18.3.2, macOS 15.3.2, and other versions.
- exploited: Apple reported awareness of exploitation in sophisticated attacks against targeted individuals on iOS versions prior to 17.2.