Threat Research Knowledge Base Vulnerabilities CVE-2025-30427
CVE-2025-30427
Description
CVE-2025-30427 is a use-after-free vulnerability in WebKit, Apple's browser engine. Processing maliciously crafted web content may lead to an unexpected Safari crash. Apple addressed this vulnerability by implementing improved memory management in Safari 18.4, macOS Sequoia 15.4, iOS 18.4, iPadOS 18.4, iPadOS 17.7.6, tvOS 18.4, and visionOS 2.4.
Impact
Exploitation of this vulnerability could lead to unexpected application termination, potentially affecting the user experience. The severity of this issue has been assessed as follows:
CISA-ADP assessment
CVSS v3.1 Base Score: 4.3 (Medium)
AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Has been exploited in the wild
No
Operating systems impacted
- macOS Sequoia (prior to 15.4)
- iOS (prior to 18.4)
- iPadOS (prior to 18.4)
- iPadOS 17 (prior to 17.7.6)
- tvOS (prior to 18.4)
- visionOS (prior to 2.4)
Additional resources
Apps impacted
- Safari (prior to 18.4)
Related
Exploitation of this vulnerability could lead to unauthorized access to sensitive location information by an application. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could lead to a denial-of-service condition by causing unexpected application termination. The severity of this issue has been assessed as follows:
Exploitation of this vulnerability could allow attackers to execute arbitrary code on the affected devices, leading to potential data breaches, unauthorized access, or further compromise of the system. Apple has acknowledged reports that this issue may have been exploited in extremely sophisticated attacks against specific targeted individuals on versions of iOS before iOS 17.2. The severity of this issue has been assessed as follows:
Manage and secure your Apple devices at scale.
