Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-24201

74
FAUCET Score

CVE-2025-24201 is a critical out-of-bounds write vulnerability in WebKit, affecting various Apple products including Safari, iOS, iPadOS, macOS, visionOS, and watchOS, as well as Debian. Maliciously crafted web content can exploit this flaw to break out of the Web Content sandbox, potentially leading to arbitrary code execution. Rated with a CVSS score of 10.0 (Critical), this vulnerability has a network attack vector, low attack complexity, and requires no privileges or user interaction beyond accessing malicious content, resulting in high impacts to confidentiality, integrity, and availability. This zero-day vulnerability is actively exploited in the wild, with Apple confirming its use in sophisticated, targeted attacks against specific individuals on older iOS versions and suspected exploitation against iOS 18 devices. Despite active exploitation, no public exploit code is currently available, though it has garnered significant community and media attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 18.3.1CPE matchmatch criteria
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
>= 15.0, < 15.3.2CPE matchmatch criteria
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
< 2.3.2CPE matchmatch criteria
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
< 11.4CPE matchmatch criteria
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
>= 15.8, < 15.8.4CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.24%
Probability of exploitation in next 30 days
EPSS Percentile
90.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 13, 2025
This CVE's current EPSS score of 0.0424 is in the 83rd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (17)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 134.0.3124.62
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: webkit2gtk3-0:2.46.6-2.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: webkit2gtk3-0:2.46.6-2.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: webkit2gtk3-0:2.46.6-2.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: webkit2gtk3-0:2.46.6-2.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: webkit2gtk3-0:2.46.6-2.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: webkit2gtk3-0:2.46.6-2.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: webkit2gtk3-0:2.46.6-2.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: webkitgtk4-0:2.48.3-2.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: webkit2gtk3-0:2.46.6-2.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: webkit2gtk3-0:2.46.6-2.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: webkit2gtk3-0:2.46.6-2.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: webkit2gtk3-0:2.46.6-2.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: webkit2gtk3-0:2.46.6-2.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: webkit2gtk3-0:2.46.6-2.el8_6
View patch
applevendor investigatingvia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: webkitgtk3

Vendor Advisories (2)

microsoft2025-Mar/CVE-2025-24201

Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac

Mar 11, 2025
redhatCVE-2025-24201Important

webkitgtk: out-of-bounds write vulnerability

Mar 11, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
seclists.org / fulldisclosure/2025/Apr/16
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Apr/7
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Jun/19
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Mar/2
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Mar/3
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Mar/4
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Mar/5
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Oct/1
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2025/Oct/31
Mailing ListThird Party Advisory
github.com / cisagov/vulnrichment/issues/194
Issue Tracking
github.com / JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/06/msg00016.html
Mailing List
support.apple.com / en-us/122281
Release NotesVendor Advisory
support.apple.com / en-us/122283
Release NotesVendor Advisory
support.apple.com / en-us/122284
Release NotesVendor Advisory
support.apple.com / en-us/122285
Release NotesVendor Advisory
support.apple.com / en-us/122345
Release NotesVendor Advisory
support.apple.com / en-us/122346
Release NotesVendor Advisory
support.apple.com / en-us/122372
Release NotesVendor Advisory
support.apple.com / en-us/122376
Release NotesVendor Advisory