CVE-2025-24180
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Mar 31, 2025
Updated: Apr 7, 2025
CWE ID 601
Summary
CVE-2025-24180 is a vulnerability affecting WebAuthn, a standard for passwordless authentication. The flaw, now mitigated, allowed a malicious website to hijack WebAuthn credentials from another site sharing a registrable suffix. This could potentially expose users' sensitive information. The vulnerability has been resolved in Safari 18.4, visionOS 2.4, iOS 18.4, and iPadOS 18.4, as well as macOS Sequoia 15.4. Input validation enhancements were applied to address the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.