CVE-2025-24201
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2025-24201. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.1EPSS Score
v2025.03.14There is a 0.0% chance that this vulnerability will be exploited in the wild within the next 30 days.
Attack Vector Metrics
Impact Metrics
Description
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, watchOS 11.4, iPadOS 17.7.6, iOS 16.7.11 and iPadOS 16.7.11, iOS 15.8.4 and iPadOS 15.8.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
Available Exploits
Related News
Posted by josephgoyd via Fulldisclosure on Jun 17"Glass Cage" – Sophisticated Zero-Click iMessage Exploit ChainEnabling Persistent iOS Compromise and Device Bricking CVE-2025-24085, CVE-2025-24201(CNVD-2025-07885) Author: Joseph Goydish II Date: 06/10/2025 …
Affected Products
Affected Versions:
Affected Versions:
Affected Versions:
Affected Versions:
Affected Versions:
Affected Versions:
Affected Versions:
Affected Versions:
Known Exploited Vulnerability
This vulnerability is actively being exploited in the wild
Remediation Status
Due Date
Added to KEV
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Affected Product
Ransomware Risk
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
Advisory Details
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: March 11, 2025, Modified: April 13, 2025
Social Media Intelligence
Real-time discussions and threat intelligence from social platforms
Prancūzija atskleidžia „Apple“ šnipinėjimo veiklą Prancūzijos nacionalinė kibernetinio saugumo agentūra ANSSI paskelbė, kad „Apple“ neseniai išsiuntė pranešimus naudotojams, kuriuos taikiniu pasirinko šnipinėjimo programos. Nuo 2021 m. „Apple“ siunčia tokio pobūdžio įspėjimus, tačiau jie yra individualūs ir neviešinami, todėl sunku nustatyti, kada atakos vyksta ir ar jos sutampa su nulinių dienų …
CVE-2025-24201 Would love to find a poc exploit or for CVE-2025-24201 or how I could go about creating one. It is the only thing patched on iOS 18.3.2 https://support.apple.com/en-us/122281
Potential Userland ROP exploit in the Switch 1/2 via CVE-2025-24201 ? So maybe softmod of the switch 1 mariko a exploit like the GoldHen on the PS4
Potential Userland ROP exploit for Switch 2 via CVE-2025-24201 ? While I don't know what webkit version the Switch 2 version uses or the Switch 1 uses, we could potentially use exploit CVE-2025-24201 According to Redhat Security about the exploit CVE-2025-24201: [https://access.redhat.com/security/cve/cve-2025-24201](https://access.redhat.com/security/cve/cve-2025-24201) >A flaw was found in WebKitGTK. Processing malicious …
🔥 Top 10 Trending CVEs (15/06/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2024-43468](https://nvd.nist.gov/vuln/detail/CVE-2024-43468)** - 📝 Microsoft Configuration Manager Remote Code Execution Vulnerability - 📅 **Published:** 08/10/2024 - 📈 **CVSS:** 9.8 - 🧭 **Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - 📣 **Mentions:** 11 - ⚠️ **Priority:** 2 --- …
🔥 Top 10 Trending CVEs (14/06/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-24201](https://nvd.nist.gov/vuln/detail/CVE-2025-24201)** - 📝 An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, …