CVE-2025-24209

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected process crash

Researchers: Francisco Alonso (@revskills), and an anonymous researcher

Attribute Value
CVE CVE-2025-24209
Bugzilla 286462
Component WebCore
Bug Class IntegerOverflow
Severity medium
Commit 575e5800d5bb2215…
Advisory Apple Advisory

Root Cause Analysis

A buffer overflow issue was addressed with improved memory handling.

Files Changed

Source Files

  • Source/WebCore/css/parser/CSSParserFastPaths.cpp

Test Files

  • LayoutTests/fast/css/transform-translate-parsing-crash-expected.txt
  • LayoutTests/fast/css/transform-translate-parsing-crash.html