ZDI-25-048: Apple WebKit WebCore ContainerNode Use-After-Free Remote Code Execution Vulnerability
Published Jan 20, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-27856.
Affected Software
1 affected component
Apple WebKit
Event History
Jan 20, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-048?
The severity of ZDI-25-048 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-25-048?
To fix ZDI-25-048, ensure that you update to the latest version of Apple WebKit.
3
What type of attacks can be executed using ZDI-25-048?
ZDI-25-048 can allow remote attackers to execute arbitrary code on affected installations.
4
Is user interaction required for exploiting ZDI-25-048?
Yes, user interaction is required to successfully exploit ZDI-25-048.
5
What CVE is associated with ZDI-25-048?
The CVE associated with ZDI-25-048 is CVE-2024-27856.