CVE-2025-24180

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 7, 2025
CWE ID 601

Summary

CVE-2025-24180 is a vulnerability affecting WebAuthn, a standard for passwordless authentication. The flaw, now mitigated, allowed a malicious website to hijack WebAuthn credentials from another site sharing a registrable suffix. This could potentially expose users' sensitive information. The vulnerability has been resolved in Safari 18.4, visionOS 2.4, iOS 18.4, and iPadOS 18.4, as well as macOS Sequoia 15.4. Input validation enhancements were applied to address the issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share