Threat Research Knowledge Base Vulnerabilities CVE-2025-24162
CVE-2025-24162
Description
CVE-2025-24162 is a vulnerability in Apple's WebKit engine that could lead to an unexpected process crash when processing maliciously crafted web content. The issue was addressed by Apple through improved state management in the affected systems.
Impact
Exploitation of this vulnerability could lead to a denial-of-service condition by causing unexpected application termination. The severity of this issue has been assessed as follows:
NIST assessment
CVSS v3.1 Base Score: 6.5 (Medium)
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA-ADP assessment
CVSS v3.1 Base Score: 6.5 (Medium)
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Has been exploited in the wild
No
Operating systems impacted
- macOS Sequoia (prior to 15.3)
- iOS (prior to 18.3)
- iPadOS (prior to 18.3)
- visionOS (prior to 2.3)
- watchOS (prior to 11.3)
- tvOS (prior to 18.3)
Additional resources
Apps impacted
- Safari (prior to 18.3)
Related
Grants unauthorized access to sensitive user information. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to a download's origin being incorrectly associated, potentially allowing malicious websites to bypass security restrictions. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could allow attackers to execute arbitrary code on the affected devices, leading to potential data breaches, unauthorized access, or further compromise of the system. Apple has acknowledged reports that this issue may have been exploited in extremely sophisticated attacks against specific targeted individuals on versions of iOS before iOS 17.2. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
