CVE-2025-24180

Overview

Advisory: Apple Security Advisory

Impact:

Description: A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix

Researchers: Martin Kreichgauer of Google Chrome

Attribute Value
CVE CVE-2025-24180
Bugzilla None
Component WebKit
Bug Class LogicError
Severity medium
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved input validation.