CVE-2025-24169: Race Condition
Published Jan 27, 2025
·Updated
A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass browser extension authentication.
Credit
Song Hyun Bae@@bshyuunn, Lee Dong Ha (Who4mI), Kirin@@Pwnrin, Wang Yu(Cyberserval), Matej Moravec@@MacejkoMoravec, Arsenii Kostromin (0x3c3e), Joshua Jones, DongJun Kim@@smlijun, JongSeong Kim in Enki WhiteHat@@nevul37, D4m0n, Mateusz Krzywicki@@krzywix, Joseph Ravichandran@@0xjprx(MIT CSAIL), an anonymous researcher, pattern-f@@pattern_F_, Michael (Biscuit) Thomas @social.lol)@@biscuit, Ivan Fratric(Google Project Zero), 风(binary_fmyy), Minghao Lin@(Y1nKoc), Mickey Jin@@patch1t, Pedro Tôrres@@t0rr3sp3dr0, Josh Parnham@@joshparnham, 神罚@@Pwnrin, @@RenwaX23, Michael DePlante@@izobashi(Trend Micro Zero Day Initiative), Zhongquan Li@@Guluisacat, Hossein Lotfi@@hosselot(Trend Micro Zero Day Initiative), Junsung Lee, Rodolphe BRUNETTI@@eisw0lf(Lupus Nova), Yann GASCUEL(Alter Solutions), Adam M., Q1IQ@@q1iqF(NUS CuriOSity), P1umer@@p1umer(Imperial Global Singapore), linjy(HKUS3Lab), chluo(WHUSecLab), Johan Carlsson (joaxcar), PixiePoint Security, Bohdan Stasiuk@@Bohdan_Stasiuk, Minghao Lin@@Y1nKoc(Zhejiang University), babywu(Zhejiang University), (Zhejiang University), Xingwei Lin(Zhejiang University), Google Threat Analysis Group, Desmond(Trend Micro Zero Day Initiative), Pwn2car & Rotiple (HyeongSeok Jang)(Trend Micro Zero Day Initiative), CVE-2025-24085, Uri Katz (Oligo Security)
Affected Software
6 affected componentsFixes available
apple macOS Sequoia<15.3
apple Safari
apple Safari<18.3
Apple macOS<15.3
apple macOS Sequoia<15.3
15.3
apple Safari<18.3
18.3
Event History
Jan 27, 2025
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Updated
via Apple·12:00 AM
Description
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24169?
CVE-2025-24169 addresses critical vulnerabilities including a logging issue and a null pointer dereference that pose risks to macOS Sequoia and Safari.
2
How do I fix CVE-2025-24169?
To fix CVE-2025-24169, update macOS Sequoia to version 15.3 and Safari to version 18.3.
3
What vulnerabilities does CVE-2025-24169 address?
CVE-2025-24169 addresses logging issues, browser extension authentication bypass, and input validation vulnerabilities.
4
Which versions are affected by CVE-2025-24169?
CVE-2025-24169 affects macOS Sequoia versions prior to 15.3 and Safari versions prior to 18.3.
5
What products are impacted by CVE-2025-24169?
CVE-2025-24169 impacts Apple macOS Sequoia and Apple Safari.