🟢 CVE-2025-24201

An out-of-bounds write vulnerability in Apple's WebKit engine allows maliciously crafted web content to break out of the Web Content sandbox. This affects client devices (iOS, macOS, Safari) when users visit malicious websites, not internet-facing servers.

← Back to Overview
LOW_RISK
Risk Level
10.0
CVSS Score
NETWORK
Attack Vector
Execution
ATT&CK Tactic
T1203 — Exploitation for Client Execution
ATT&CK Technique
VERY_LOW
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: USER_INTERACTION

CVE Published: 2025-03-11

Added to CISA KEV: 2025-03-13 2 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2025-24201 is a security vulnerability in Apple's WebKit that allows an attacker to escape the Web Content sandbox [1] [2].

Key Details
FeatureDescription
Vulnerability TypeOut-of-bounds write in web content processing [2]
ExploitationActively exploited in the wild in highly sophisticated, targeted attacks [1] [3]
MethodRemote exploitation via maliciously crafted web content [2]
ImpactSandbox escape and potential arbitrary code execution on the device [2]
StatusIncluded in CISA’s Known Exploited Vulnerabilities (KEV) Catalog [1]
Additional Information
  • Active Exploitation & Threat Actors: Apple has acknowledged reports that this vulnerability was exploited in extremely sophisticated attacks against specific, targeted individuals on versions of iOS prior to 17.2 [1]. It is not associated with broad ransomware campaigns, but rather high-end, targeted exploitation [3].
  • Exploitation Requirements: The attack is remote and relies on the victim processing maliciously crafted web content [2].
  • Proof-of-Concept: While the vulnerability has been exploited in the wild, there is no widespread public availability of a proof-of-concept (PoC) exploit tool for general use.
  • Patch Status: This vulnerability was addressed as a supplementary fix for an attack previously blocked in iOS 17.2 [1]. Users are strongly advised to ensure their Apple devices are updated to the latest available software versions to mitigate this and other security risks [3].

Sources

  1. CVE-2025-24201 Detail - NVD

    Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple ... This CVE is in CISA's Known Exploited Vulnerabilities Catalog Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for…

  2. CVE-2025-24201 - Exploits & Severity - Feedly

    Summary. An out-of-bounds write vulnerability in web content processing that could allow attackers to break out of the Web Content sandbox. This is a supplementary fix for a previously blocked attack in iOS 17.2, with indications that it may have been exploited in a sophisticated targeted attack. Im…

  3. CVE-2025-24056 - Exploits & Severity - Feedly

    Feedly estimated the CVSS as HIGH based on the CVE details, attack complexity, and exploit information. ... A zero-day vulnerability (CVE-2025-24201) in Apple s WebKit has been actively exploited, highlighting advanced targeting of Apple products with complex techniques, underscoring the urgency of…