CVE-2025-24209: Buffer Overflow
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected process crash.
Other sources
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 18.4, Safari 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may lead to an unexpected process crash.
— Debian
Accessibility. A logging issue was addressed with improved data redaction.
— Apple
AccountPolicy. This issue was addressed by removing the vulnerable code.
— Apple
Accounts. This issue was addressed with improved data access restriction.
— Apple
AirDrop. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 18.4 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.48.1-2~deb12u1Fixed in 2.48.1-2 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.48.1-1 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 11.4 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 18.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 18.4 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 18.4 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 15.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.7.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2025-24180
- CVE-2025-24113
- CVE-2025-30467
- CVE-2025-31192
- CVE-2025-24167
- CVE-2025-31184
- CVE-2025-24192
- CVE-2025-24264
- CVE-2025-24216
- CVE-2025-24213
- CVE-2025-24209
- CVE-2025-24208
- CVE-2025-30427
- CVE-2025-30425
- CVE-2025-24097
- CVE-2025-24251
- CVE-2025-24244
- CVE-2025-24243
- CVE-2025-30430
- CVE-2025-24237
- CVE-2025-30429
- CVE-2025-24212
- CVE-2025-24163
- CVE-2025-24230
- CVE-2025-24190
- CVE-2025-30454
- CVE-2025-31191
- CVE-2025-24182
- CVE-2025-31203
- CVE-2024-9681
- CVE-2025-30439
- CVE-2025-24283
- CVE-2025-30447
- CVE-2025-24210
- CVE-2025-24257
- CVE-2025-30432
- CVE-2024-48958
- CVE-2025-24194
- CVE-2025-27113
- CVE-2024-56171
- CVE-2025-24178
- CVE-2025-31182
- CVE-2025-24238
- CVE-2025-30470
- CVE-2025-30426
- CVE-2025-24173
- CVE-2025-30471
- CVE-2025-30438
- CVE-2025-30433
- CVE-2025-31183
- CVE-2025-24217
- CVE-2025-24214
- CVE-2025-24201
- CVE-2025-24202
- CVE-2025-24221
- CVE-2025-24271
- CVE-2025-24270
- CVE-2025-31202
- CVE-2025-24252
- CVE-2025-24206
- CVE-2025-30445
- CVE-2025-31197
- CVE-2025-24211
- CVE-2025-30456
- CVE-2025-30463
- CVE-2025-30434
- CVE-2025-24193
- CVE-2025-30428
- CVE-2025-30469
- CVE-2025-24095
- CVE-2025-24205
- CVE-2025-24198
- CVE-2025-24234
- CVE-2025-24276
- CVE-2025-24272
- CVE-2025-24239
- CVE-2025-24233
- CVE-2025-30443
- CVE-2025-24245
- CVE-2025-30460
- CVE-2025-24215
- CVE-2025-24236
- CVE-2025-24277
- CVE-2025-24255
- CVE-2025-24267
- CVE-2025-30455
- CVE-2025-31187
- CVE-2025-30462
- CVE-2025-30451
- CVE-2025-24281
- CVE-2025-30461
- CVE-2025-24199
- CVE-2025-30464
- CVE-2025-24273
- CVE-2025-24256
- CVE-2025-24249
- CVE-2025-24229
- CVE-2025-30437
- CVE-2025-24235
- CVE-2025-24204
- CVE-2025-24203
- CVE-2025-24196
- CVE-2025-24148
- CVE-2025-24195
- CVE-2025-24172
- CVE-2025-30450
- CVE-2025-24262
- CVE-2025-24232
- CVE-2025-24246
- CVE-2025-24261
- CVE-2025-24164
- CVE-2025-30446
- CVE-2025-24259
- CVE-2025-30424
- CVE-2023-27043
- CVE-2025-24191
- CVE-2025-24093
- CVE-2025-30452
- CVE-2025-24181
- CVE-2025-30458
- CVE-2025-24250
- CVE-2025-30465
- CVE-2025-24280
- CVE-2025-31194
- CVE-2025-30435
- CVE-2025-24248
- CVE-2025-24269
- CVE-2025-30444
- CVE-2025-24228
- CVE-2025-24260
- CVE-2025-24282
- CVE-2025-24254
- CVE-2025-24231
- CVE-2025-24263
- CVE-2025-24207
- CVE-2025-30449
- CVE-2025-24253
- CVE-2025-24240
- CVE-2025-31188
- CVE-2025-24218
- CVE-2025-24278
- CVE-2025-24242
- CVE-2025-30457
- CVE-2025-24279
- CVE-2025-24247
- CVE-2025-24241
- CVE-2025-24266
- CVE-2025-24265
- CVE-2025-24157
- CVE-2025-30466
- CVE-2025-24131
- CVE-2025-24177
- CVE-2025-24179
- CVE-2025-43205
- CVE-2025-24085
- CVE-2024-54543
- CVE-2024-54534
- CVE-2024-54508
- CVE-2024-54502
- CVE-2025-31196
- CVE-2025-31272
- CVE-2025-24170
- CVE-2025-31189
- CVE-2025-30453
- CVE-2025-24258
- CVE-2025-30431
- CVE-2025-30448
- CVE-2025-31263
- CVE-2025-31231
- CVE-2025-31199
- CVE-2025-31264
- CVE-2025-46308
- CVE-2025-24284
- CVE-2025-30459
- CVE-2025-24268
- CVE-2025-43184
- CVE-2025-24165
- CVE-2025-30442
- CVE-2025-31261
- CVE-2025-46293
- CVE-2025-43278
- CVE-2025-31195
- CVE-2025-31198
- CVE-2025-24220
- CVE-2025-30436
Frequently Asked Questions
What is the severity of CVE-2025-24209?
CVE-2025-24209 has been classified as a buffer overflow vulnerability that could lead to unexpected process crashes.
How do I fix CVE-2025-24209?
To fix CVE-2025-24209, update to the latest versions of affected products such as tvOS 18.4, iOS 18.4, iPadOS 18.4, Safari 18.4, and macOS Sequoia 15.4.
What products are affected by CVE-2025-24209?
CVE-2025-24209 affects several Apple products including Safari, iOS, iPadOS, tvOS, and macOS Sequoia.
What causes CVE-2025-24209?
CVE-2025-24209 is caused by a buffer overflow due to improper handling of maliciously crafted web content.
What are the consequences of CVE-2025-24209?
The consequences of CVE-2025-24209 include potential process crashes of applications processing web content.