This vulnerability, an out-of-bounds write issue, could allow attackers to execute unauthorized code on vulnerable devices.
The vulnerability lies within WebKit, a cross-platform web browser engine used by Safari and other applications across macOS, iOS, Linux, and Windows.
CVE-2025-24201 can be exploited through maliciously crafted web content, potentially allowing attackers to break out of the Web Content sandbox.
This could lead to unauthorized actions, further exploitation, remote code execution, or even the deployment of spyware on affected devices.
The vulnerability impacts a wide array of Apple devices, including:
The vulnerability also affects third-party browsers on iOS and iPadOS, which are required to use WebKit.
Apple has acknowledged that CVE-2025-24201 may have been exploited in “extremely sophisticated” attacks targeting specific individuals on versions of iOS before 17.2.
While Apple has not released specific details regarding the attacks, they appear to be highly targeted rather than widespread3. This is the third zero-day vulnerability Apple has addressed in 2025.
Apple has released updates to address the vulnerability, including improved checks to prevent unauthorized actions:
CISA recommends applying mitigations per vendor instructions, following applicable BOD 22-01 guidance for cloud services, or discontinuing use of the product if mitigations are unavailable.
Users are advised to update their devices immediately to the latest software versions. For enterprise and high-risk users, enabling Lockdown Mode is recommended to harden device security against targeted attacks.
To protect against potential exploitation, users should take the following precautions:
Are you from SOC/DFIR Teams? – Analyse Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.
The post CISA Warns of Apple WebKit Out-of-Bounds Write Vulnerability Exploited in Wild appeared first on Cyber Security News.
MACHESNEY PARK, Ill. (WTVO) — As the Harlem School District grapples with fixing a budget…
Two men have been charged with first-degree murder in connection with a 2021 deadly shooting…
Journalist Julia Angwin is one of the writers whose likeness was used in Grammarly’s “expert…
The U.S. Supreme Court on Oct. 9, 2024. (Photo by Jane Norman/States Newsroom)WASHINGTON — The…
The folding iPhone might come with an inner display the size of an iPad Mini,…
Humble has teamed up with Frictional Games for a new bundle of PC games that…
This website uses cookies.