CVE-2025-24208

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Mar 31, 2025
Updated: Apr 7, 2025
CWE ID 79

Summary

CVE-2025-24208 is a permissions issue that has been addressed in Safari 18.4, iOS 18.4, and iPadOS 18.4. If exploited, this vulnerability could allow a malicious iframe to initiate a cross-site scripting attack. The flaw stems from insufficient restrictions on loading iframes, which can pose a security risk. By loading a specially crafted iframe, an attacker could potentially inject malicious code into a victim's web browser, compromising their data or taking control of their session. Users are advised to update their operating systems and web browsers to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share