CVE-2025-24208: Buffer Overflow
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
Other sources
Accessibility. A logging issue was addressed with improved data redaction.
— Apple
Accounts. This issue was addressed with improved data access restriction.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
AirPlay. A null pointer dereference was addressed with improved input validation.
— Apple
AirPlay. A type confusion issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24180
- CVE-2025-24113
- CVE-2025-30467
- CVE-2025-31192
- CVE-2025-24167
- CVE-2025-31184
- CVE-2025-24192
- CVE-2025-24264
- CVE-2025-24216
- CVE-2025-24213
- CVE-2025-24209
- CVE-2025-24208
- CVE-2025-30427
- CVE-2025-30425
- CVE-2025-24202
- CVE-2025-24221
- CVE-2025-24097
- CVE-2025-24271
- CVE-2025-24270
- CVE-2025-31202
- CVE-2025-24252
- CVE-2025-24206
- CVE-2025-30445
- CVE-2025-24251
- CVE-2025-31197
- CVE-2025-24244
- CVE-2025-24243
- CVE-2025-30430
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24163
- CVE-2025-24230
- CVE-2025-24211
- CVE-2025-24190
- CVE-2025-30454
- CVE-2025-31191
- CVE-2025-24182
- CVE-2025-31203
- CVE-2024-9681
- CVE-2025-30456
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-30447
- CVE-2025-30463
- CVE-2025-24210
- CVE-2025-24257
- CVE-2025-30434
- CVE-2025-30432
- CVE-2024-48958
- CVE-2025-24194
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-30470
- CVE-2025-24193
- CVE-2025-30426
- CVE-2025-30428
- CVE-2025-30469
- CVE-2025-24173
- CVE-2025-24095
- CVE-2025-30471
- CVE-2025-30438
- CVE-2025-30433
- CVE-2025-31183
- CVE-2025-24217
- CVE-2025-24214
- CVE-2025-24205
- CVE-2025-24198
- CVE-2025-30466
- CVE-2025-43205
- CVE-2025-31196
- CVE-2025-24203
- CVE-2025-31199
- CVE-2025-46308
- CVE-2025-24220
- CVE-2025-30436
Frequently Asked Questions
What is the severity of CVE-2025-24208?
CVE-2025-24208 has been categorized as a medium severity vulnerability.
How do I fix CVE-2025-24208?
To fix CVE-2025-24208, upgrade to Safari 18.4, iOS 18.4, or iPadOS 18.4.
What type of vulnerability is CVE-2025-24208?
CVE-2025-24208 is a permissions issue that could lead to a cross-site scripting attack.
Which versions are affected by CVE-2025-24208?
CVE-2025-24208 affects versions earlier than Safari 18.4, iOS 18.4, and iPadOS 18.4.
Can CVE-2025-24208 be exploited remotely?
Yes, CVE-2025-24208 can be exploited remotely through a malicious iframe.