CVE-2025-24216

Overview

Advisory: Apple Security Advisory

Impact:

Description: Processing maliciously crafted web content may lead to an unexpected Safari crash

Researchers: Paul Bakker of ParagonERP

Attribute Value
CVE CVE-2025-24216
Bugzilla 284055
Component WebCore
Bug Class LogicError
Severity medium
Commit b879a659b19009b9…
Advisory Apple Advisory

Root Cause Analysis

The issue was addressed with improved memory handling.

Files Changed

Source Files

  • Source/WebCore/css/CSSSelector.h
  • Source/WebCore/css/CSSStyleSheet.cpp
  • Source/WebCore/css/SelectorChecker.cpp
  • Source/WebCore/css/StyleSheetContents.h
  • Source/WebCore/style/RuleSetBuilder.cpp
  • Source/WebCore/style/RuleSetBuilder.h

Test Files

  • LayoutTests/fast/selectors/has-nesting-crash-expected.txt
  • LayoutTests/fast/selectors/has-nesting-crash.html