Back to Labs
Security Advisory

CVE-2025-24201

About

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).

Weakness (CWE):CWE-787

Rainforest analyst review

This is an out-of-bounds write in WebKit, Apple's browser engine, that lets maliciously crafted web content write past the bounds of a buffer and break out of the Web Content sandbox — the isolation layer meant to keep a compromised page renderer from touching the rest of the device. Apple describes it as a supplementary fix, hardening against an attack that an earlier mitigation in iOS 17.2 had blocked, which means adversaries had found a way around the original defense.

Apple states the issue may have been exploited in an extremely sophisticated attack against specific, targeted individuals — the signature of mercenary spyware, where a sandbox escape is one link in a chain aimed at full device takeover. This is not a mass-scanning threat; the risk is concentrated on journalists, activists, and officials likely to be targeted. Install the fixed iOS, iPadOS, macOS, visionOS, watchOS, and Safari updates promptly, and for high-risk users enable Lockdown Mode, which is designed to shut down exactly this class of WebKit attack surface.

References

Related CVEs

Frequently asked questions

What is CVE-2025-24201?

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox.

How severe is CVE-2025-24201?

CVE-2025-24201 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.

How is CVE-2025-24201 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2025-24201?

Public advisories list the following as affected: debian linux, ipados, iphone os, macos, safari, visionos, +1. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2025-24201?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email