CVE-2025-24201: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Accessibility. An authorization issue was addressed with improved state management.
Other sources
Accounts. This issue was addressed with improved data access restriction.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
AirPlay. A use-after-free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
visionOSto a version that resolves this vulnerability.Fixed in 2.3.2 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 15.3.2 - Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 134.0.6998.88 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 18.3.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.3.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.3.2 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 135.0.7049.52-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.48.0-1~deb12u1Fixed in 2.48.0-1Fixed in 2.48.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.48.0-1Fixed in 2.48.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in Safari 18.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 15.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 15.8.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 16.7.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 16.7.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 18.3.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 18.3.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 17.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.3.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.3.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2025-24201 - Compensating control
If mitigations are unavailable, discontinue use of the affected Apple product. (Mitigations per vendor instructions; follow applicable BOD 22-01 guidance for cloud services.)
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24201
- CVE-2025-1920
- CVE-2025-2135
- CVE-2025-2136
- CVE-2025-2137
- CVE-2025-31200
- CVE-2025-31201
- CVE-2025-24085
- CVE-2025-24200
- CVE-2025-43200
- CVE-2025-24221
- CVE-2025-24131
- CVE-2025-24270
- CVE-2025-24271
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24252
- CVE-2025-30445
- CVE-2025-24206
- CVE-2025-43205
- CVE-2025-24243
- CVE-2025-24244
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24215
- CVE-2025-24230
- CVE-2025-24190
- CVE-2025-24211
- CVE-2025-31203
- CVE-2024-9681
- CVE-2025-30447
- CVE-2025-24210
- CVE-2025-30432
- CVE-2025-24203
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-30426
- CVE-2025-30428
- CVE-2025-24173
- CVE-2025-24113
- CVE-2025-30471
- CVE-2025-30465
- CVE-2025-30433
- CVE-2025-24198
- CVE-2025-24205
- CVE-2025-30425
- CVE-2025-24216
- CVE-2025-24264
- CVE-2025-30427
- CVE-2025-24209
- CVE-2024-54543
- CVE-2024-54534
- CVE-2024-54508
- CVE-2024-54502
- CVE-2025-24097
- CVE-2025-30430
- CVE-2025-24180
- CVE-2025-24163
- CVE-2025-31196
- CVE-2025-30454
- CVE-2025-31191
- CVE-2025-24182
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-24257
- CVE-2024-48958
- CVE-2025-24194
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-30470
- CVE-2025-30467
- CVE-2025-24167
- CVE-2025-30438
- CVE-2025-31183
- CVE-2025-24217
- CVE-2025-24214
Frequently Asked Questions
What is the severity of CVE-2025-24201?
CVE-2025-24201 is considered a critical vulnerability due to its potential to allow unauthorized actions through an out-of-bounds write issue.
How do I fix CVE-2025-24201?
To mitigate CVE-2025-24201, upgrade to visionOS 2.3.2, iOS 18.3.2, iPadOS 18.3.2, or macOS Sequoia 15.3.2.
What software versions are affected by CVE-2025-24201?
CVE-2025-24201 affects versions of visionOS prior to 2.3.2, iOS prior to 18.3.2, iPadOS prior to 18.3.2, and macOS Sequoia prior to 15.3.2.
What type of attack can exploit CVE-2025-24201?
CVE-2025-24201 can be exploited through maliciously crafted web content allowing it to escape the Web Content sandbox.
Which Apple product requires an update to address CVE-2025-24201?
Apple products including visionOS, iOS, iPadOS, macOS Sequoia, and Safari require an update to address CVE-2025-24201.