CVE-2025-24162

T

his issue was addressed through improved state management. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

03 Nov 2025, 21:19

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2025/Jan/13 -
  • () http://seclists.org/fulldisclosure/2025/Jan/15 -
  • () http://seclists.org/fulldisclosure/2025/Jan/18 -
  • () http://seclists.org/fulldisclosure/2025/Jan/20 -
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00014.html -

18 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-125

03 Mar 2025, 22:45

Type Values Removed Values Added
References () https://support.apple.com/en-us/122066 - () https://support.apple.com/en-us/122066 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122068 - () https://support.apple.com/en-us/122068 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122071 - () https://support.apple.com/en-us/122071 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122072 - () https://support.apple.com/en-us/122072 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122073 - () https://support.apple.com/en-us/122073 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/122074 - () https://support.apple.com/en-us/122074 - Release Notes, Vendor Advisory
First Time Apple visionos
Apple ipados
Apple macos
Apple safari
Apple tvos
Apple iphone Os
Apple
Apple watchos
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

18 Feb 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown

28 Jan 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Este problema se solucionó mediante con una mejor gestión del estado. Este problema se solucionó en visionOS 2.3, Safari 18.3, iOS 18.3 y iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3 y tvOS 18.3. El procesamiento malintencionado de contenido web manipulado puede provocar un bloqueo inesperado del proceso.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2025-11-03 21:19


NVD link : CVE-2025-24162

Mitre link : CVE-2025-24162

CVE.ORG link : CVE-2025-24162


JSON object : View

CWE
NVD-CWE-noinfo CWE-125

Out-of-bounds Read