ZDI-CAN-24012: ZDI-25-048: Apple WebKit WebCore ContainerNode Use-After-Free Remote Code Execution Vulnerability
Published Jan 20, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-27856.
Affected Software
1 affected component
Apple WebKit
Event History
Jan 20, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-24012?
The severity of ZDI-CAN-24012 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-CAN-24012?
To fix ZDI-CAN-24012, ensure that you update your Apple WebKit installation to the latest version provided by Apple.
3
What type of attack does ZDI-CAN-24012 involve?
ZDI-CAN-24012 involves remote code execution that requires user interaction to exploit.
4
Which software is affected by ZDI-CAN-24012?
ZDI-CAN-24012 affects installations of Apple WebKit.
5
Is user interaction necessary to exploit ZDI-CAN-24012?
Yes, user interaction is required to successfully exploit ZDI-CAN-24012.