CVE-2025-24209
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may lead to an unexpected process crash
Researchers: Francisco Alonso (@revskills), and an anonymous researcher
| Attribute | Value |
|---|---|
| CVE | CVE-2025-24209 |
| Bugzilla | 286462 |
| Component | WebCore |
| Bug Class | IntegerOverflow |
| Severity | medium |
| Commit | 575e5800d5bb2215… |
| Advisory | Apple Advisory |
Root Cause Analysis
A buffer overflow issue was addressed with improved memory handling.
Files Changed
Source Files
Source/WebCore/css/parser/CSSParserFastPaths.cpp
Test Files
LayoutTests/fast/css/transform-translate-parsing-crash-expected.txtLayoutTests/fast/css/transform-translate-parsing-crash.html