CVE-2025-24201

Overview

Advisory: Apple Security Advisory

Impact:

Description: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)

Researchers: Apple

Attribute Value
CVE CVE-2025-24201
Bugzilla 285858
Component WebKit
Bug Class OOB
Severity medium
Commit 7d784721e440d049…
Advisory Apple Advisory

Root Cause Analysis

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.