CVE-2025-24180
Overview
Advisory: Apple Security Advisory
Impact:
Description: A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix
Researchers: Martin Kreichgauer of Google Chrome
| Attribute | Value |
|---|---|
| CVE | CVE-2025-24180 |
| Bugzilla | None |
| Component | WebKit |
| Bug Class | LogicError |
| Severity | medium |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved input validation.