First published: Mon Jan 27 2025(Updated: )
A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.
Credit: Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) Josh Parnham @joshparnham @RenwaX23 an anonymous researcher Michael DePlante @izobashi Trend Micro Zero Day InitiativeKirin @Pwnrin Uri Katz (Oligo Security) Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityGoogle Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n pattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit Hichem Maloufi Hakim Boukhadra mastersplinter Abhay Kailasia @abhay_kailasia C product-security@apple.com Pedro Tôrres @t0rr3sp3dr0 神罚 @Pwnrin Zhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsArsenii Kostromin (0x3c3e) Adam M. PixiePoint Security Wang Yu CyberservalMatej Moravec @MacejkoMoravec Joshua Jones Joseph Ravichandran @0xjprx MIT CSAIL云散 Mickey Jin @patch1t Bohdan Stasiuk @Bohdan_Stasiuk
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mobile Safari | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple iOS, iPadOS, and watchOS | <18.3 | 18.3 |
Apple Mobile Safari | <18.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
iStyle @cosme iPhone OS | <18.3 | |
Apple iOS and macOS | <15.3 | |
macOS | <15.3 | |
Apple Mobile Safari | <18.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
Apple iOS, iPadOS, and watchOS | <18.3 | |
macOS | <15.3 | 15.3 |
debian/webkit2gtk | <=2.44.2-1~deb11u1<=2.46.5-1~deb12u1 | 2.46.6-1~deb11u1 2.46.6-1~deb12u1 2.46.6-1 |
debian/wpewebkit | <=2.38.6-1~deb11u1<=2.38.6-1 | 2.46.6-1 |
<18.3 | ||
<18.3 | ||
<18.3 | ||
<15.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24150 is classified as a privacy issue affecting several Apple products.
To fix CVE-2025-24150, update to macOS Sequoia 15.3, Safari 18.3, iOS 18.3, or iPadOS 18.3.
CVE-2025-24150 affects macOS Sequoia, Safari, iOS, and iPadOS prior to their respective versions 15.3 and 18.3.
CVE-2025-24150 addresses a privacy issue related to the handling of files and a potential command injection via Web Inspector.
There are no official workarounds for CVE-2025-24150; updating to the latest versions is recommended.