First published: Mon Jan 27 2025(Updated: )
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.3, Safari 18.3. A malicious app may be able to bypass browser extension authentication.
Credit: Josh Parnham @joshparnham @RenwaX23 an anonymous researcher Q1IQ @q1iqF NUS CuriOSityP1umer @p1umer Imperial Global Singaporelinjy HKUS3Labchluo WHUSecLabJohan Carlsson (joaxcar) product-security@apple.com Pedro Tôrres @t0rr3sp3dr0 神罚 @Pwnrin Michael DePlante @izobashi Trend Micro Zero Day InitiativeZhongquan Li @Guluisacat Hossein Lotfi @hosselot Trend Micro Zero Day InitiativeRodolphe BRUNETTI @eisw0lf Lupus NovaYann GASCUEL Alter SolutionsArsenii Kostromin (0x3c3e) Kirin @Pwnrin Adam M. PixiePoint Security Minghao Lin @Y1nKoc Zhejiang Universitybabywu Zhejiang University Zhejiang UniversityXingwei Lin Zhejiang UniversityWang Yu CyberservalGoogle Threat Analysis Group Desmond Trend Micro Zero Day InitiativePwn2car & Rotiple (HyeongSeok Jang) Trend Micro Zero Day InitiativeCVE-2025-24085 Matej Moravec @MacejkoMoravec Joshua Jones DongJun Kim @smlijun JongSeong Kim in Enki WhiteHat @nevul37 D4m0n Joseph Ravichandran @0xjprx MIT CSAILpattern-f @pattern_F_ Michael (Biscuit) Thomas @social.lol) @biscuit 云散 Mickey Jin @patch1t Bohdan Stasiuk @Bohdan_Stasiuk Uri Katz (Oligo Security)
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <18.3 | 18.3 |
Apple Safari | <18.3 | |
Apple macOS | <15.3 | |
Apple macOS Sequoia | <15.3 | 15.3 |
Apple macOS Sequoia | <15.3 | |
Apple Safari |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-24169 addresses critical vulnerabilities including a logging issue and a null pointer dereference that pose risks to macOS Sequoia and Safari.
To fix CVE-2025-24169, update macOS Sequoia to version 15.3 and Safari to version 18.3.
CVE-2025-24169 addresses logging issues, browser extension authentication bypass, and input validation vulnerabilities.
CVE-2025-24169 affects macOS Sequoia versions prior to 15.3 and Safari versions prior to 18.3.
CVE-2025-24169 impacts Apple macOS Sequoia and Apple Safari.