CVE-2025-24216
Overview
Advisory: Apple Security Advisory
Impact:
Description: Processing maliciously crafted web content may lead to an unexpected Safari crash
Researchers: Paul Bakker of ParagonERP
| Attribute | Value |
|---|---|
| CVE | CVE-2025-24216 |
| Bugzilla | 284055 |
| Component | WebCore |
| Bug Class | LogicError |
| Severity | medium |
| Commit | b879a659b19009b9… |
| Advisory | Apple Advisory |
Root Cause Analysis
The issue was addressed with improved memory handling.
Files Changed
Source Files
Source/WebCore/css/CSSSelector.hSource/WebCore/css/CSSStyleSheet.cppSource/WebCore/css/SelectorChecker.cppSource/WebCore/css/StyleSheetContents.hSource/WebCore/style/RuleSetBuilder.cppSource/WebCore/style/RuleSetBuilder.h
Test Files
LayoutTests/fast/selectors/has-nesting-crash-expected.txtLayoutTests/fast/selectors/has-nesting-crash.html