CVSS v3.1 Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Prediction
Documented as more likely to be exploited than 21.0% of known CVEs.
Mar 13, 2025
Apr 03, 2025
Threat Analysis
Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Remediation Directive
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
External Intelligence
https://support.apple.com/en-us/122281
https://support.apple.com/en-us/122281
https://support.apple.com/en-us/122283
https://support.apple.com/en-us/122283
https://support.apple.com/en-us/122284
https://support.apple.com/en-us/122284
https://support.apple.com/en-us/122285
https://support.apple.com/en-us/122285
National Vulnerability Database
https://nvd.nist.gov/vuln/detail/CVE-2025-24201