ZDI-CAN-26148: ZDI-25-303: Apple Safari SandboxBroker ZIP File Processing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2025-24222.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26148?
The severity of ZDI-CAN-26148 is categorized as moderate due to its reliance on user interaction for exploitation.
How do I fix ZDI-CAN-26148?
To fix ZDI-CAN-26148, users should update their Apple Safari browser to the latest version provided by Apple.
Who is affected by ZDI-CAN-26148?
ZDI-CAN-26148 affects installations of Apple Safari that are not updated to the latest security patches.
What type of attack does ZDI-CAN-26148 involve?
ZDI-CAN-26148 involves a remote attack that requires user interaction to exploit, typically by visiting a malicious website.
What information can be disclosed due to ZDI-CAN-26148?
ZDI-CAN-26148 can potentially disclose sensitive information stored in the affected Apple Safari installation.