CVE-2025-24143

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 27, 2025
Updated: Feb 4, 2025
CWE ID 862

Summary

CVE-2025-24143 is a recently identified vulnerability affecting multiple Apple operating systems, including macOS Sequoia, iOS, and iPadOS. The issue revolves around insufficient access restrictions in the file system. Malicious webpages could potentially exploit this weakness to gather user information through fingerprinting, leading to privacy concerns. Apple has released updates for macOS Sequoia 15.3, Safari 18.3, and iOS 18.3, as well as iPadOS 18.3 and visionOS 2.3, to address this vulnerability. The updates introduce improved access restrictions, effectively mitigating the risk of this issue for affected users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Apple Safari
  • MacOS
  • iPadOS

Affected Vendors

  • Apple