{"cveID":"CVE-2025-24201","vendorProject":"Apple","product":"Multiple Products","vulnerabilityName":"Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability","dateAdded":"2025-03-13","shortDescription":"Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-04-03","knownRansomwareCampaignUse":"Unknown","notes":"https://support.apple.com/en-us/122281 ; https://support.apple.com/en-us/122283 ; https://support.apple.com/en-us/122284 ; https://support.apple.com/en-us/122285 ; ; https://nvd.nist.gov/vuln/detail/CVE-2025-24201","cwes":["CWE-787"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-24201","technique":"T1189","technique_name_at_mapping":"Drive-by Compromise","mapping_type":"exploitation_technique","capability_group":"oob","comments":"An out-of-bounds zero-day flaw exists in WebKit that adversaries have been exploiting via specially crafted web content to escape the Web Content sandbox.","references":["https://socprime.com/blog/cve-2025-24201-webkit-zeroday-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2025-24201","technique":"T1456","technique_name_at_mapping":"Drive-By Compromise","mapping_type":"exploitation_technique","capability_group":"out_of_bounds","comments":"There exists an out-of-bounds zero-day flaw in WebKit that affects iOS versions prior to 17.2, as well as prior to visionOS 2.3.2, iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, and Safari 18.3.1. With this, an attacker can craft malicious web content that causes a buffer overflow.","references":["https://socprime.com/blog/cve-2025-24201-webkit-zeroday-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-24201","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"oob","comments":"An out-of-bounds zero-day flaw exists in WebKit that adversaries have been exploiting via specially crafted web content to escape the Web Content sandbox.","references":["https://socprime.com/blog/cve-2025-24201-webkit-zeroday-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"mobile","cve":"CVE-2025-24201","technique":"T1623","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"out_of_bounds","comments":"There exists an out-of-bounds zero-day flaw in WebKit that affects iOS versions prior to 17.2, as well as prior to visionOS 2.3.2, iOS 18.3.2, iPadOS 18.3.2, macOS Sequoia 15.3.2, and Safari 18.3.1. With this, an attacker can craft malicious web content that causes a buffer overflow.","references":["https://socprime.com/blog/cve-2025-24201-webkit-zeroday-vulnerability/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-mobile.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1189","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Drive-by Compromise","name_at_mapping":"Drive-by Compromise","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":3,"has_detection_strategy":true},{"id":"T1456","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Drive-By Compromise","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":0,"has_detection_strategy":false},{"id":"T1623","domains":["mobile"],"in_current_bundle":false,"live":false,"name_now":null,"name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":0,"has_detection_strategy":false}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise","mobile"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}