An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
CVE-2025-24201
Score elevated to 10.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2025-03-13), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 10.0 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
A fix is available — apply it.
- CVSS v3
- 10.0
- EG Score
- 10.0(high)
- EG Risk
- 100(Act)EG Risk 100/100SSVC: Act
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity100% × 45%Exploitation100% × 40%Automatability100% × 15%Action: Fix now — active exploitation, automatable, high impact. - EPSS
- 90.0%
- KEV
- ⚠ Exploited
Published
March 11, 2025
Last Modified
April 3, 2026
Advisory Details (10)
Auto-updated Jul 18, 2026Full Disclosure: APPLE-SA-03-31-2025-6 iOS 15.8.4 and iPadOS 15.8.4
http://seclists.org/fulldisclosure/2025/Apr/7Full Disclosure: Re: APPLE-SA-03-11-2025-2 iOS 18.3.2 and iPadOS 18.3.2
http://seclists.org/fulldisclosure/2025/Apr/16About the security content of watchOS 11.4 - Apple Support
https://support.apple.com/en-us/122376About the security content of iPadOS 17.7.6 - Apple Support
https://support.apple.com/en-us/122372About the security content of iOS 16.7.11 and iPadOS 16.7.11 - Apple Support
https://support.apple.com/en-us/122346About the security content of iOS 15.8.4 and iPadOS 15.8.4 - Apple Support
https://support.apple.com/en-us/122345About the security content of Safari 18.3.1 - Apple Support
https://support.apple.com/en-us/122285About the security content of visionOS 2.3.2 - Apple Support
https://support.apple.com/en-us/122284About the security content of macOS Sequoia 15.3.2 - Apple Support
https://support.apple.com/en-us/122283About the security content of iOS 18.3.2 and iPadOS 18.3.2 - Apple Support
https://support.apple.com/en-us/122281Vendor Advisories for CVE-2025-24201(11)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- CVE-2025-24201Microsoft Security Response Center (MSRC)
Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac
- RHSA-2025:10364Red Hat Product SecurityHigh
Red Hat Security Advisory: webkitgtk4 security update
- RHSA-2025:3034Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2025:3005Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2025:3002Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2025:3001Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2025:3000Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- RHSA-2025:2998Red Hat Product SecurityHigh
Red Hat Security Advisory: webkit2gtk3 security update
- +3 more
Patch Availability(11)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | webkitgtk-webdriver (2.48.0-0ubuntu0.24.10.1) @ oracular | 2026-07-22 | ubuntu |
| redhat | webkitgtk4-0:2.48.3-2.el7_9 | 2025-07-07 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el8_6 | 2025-03-19 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el8_2 | 2025-03-18 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el8_8 | 2025-03-18 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el9_0 | 2025-03-18 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el8_4 | 2025-03-18 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el9_4 | 2025-03-18 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el9_2 | 2025-03-18 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el9_5 | 2025-03-17 | redhat |
| redhat | webkit2gtk3-0:2.46.6-2.el8_10 | 2025-03-17 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(1)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
Data Freshness Timeline
(refreshed 95× in last 7d / 402× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 774 total refreshes for this CVE.
- 2026-07-23 02:51 UTCEG score recompute
- 2026-07-22 20:16 UTCVendor advisory
- 2026-07-22 20:16 UTCGHSA enrichment
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 16:06 UTCEG score recompute
- 2026-07-22 16:06 UTCVendor advisory
- 2026-07-22 16:06 UTCGHSA enrichment
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 11:55 UTCVendor advisory
- 2026-07-22 11:55 UTCGHSA enrichment
- 2026-07-22 07:45 UTCVendor advisory
- 2026-07-22 07:45 UTCGHSA enrichment
- 2026-07-22 03:35 UTCVendor advisory
- 2026-07-22 03:35 UTCGHSA enrichment
- 2026-07-21 23:25 UTCVendor advisory
- 2026-07-21 23:24 UTCGHSA enrichment
- 2026-07-21 18:17 UTCEG score recompute
- 2026-07-21 18:17 UTCVendor advisory
- 2026-07-21 18:17 UTCGHSA enrichment
- 2026-07-21 15:24 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-21 14:06 UTCVendor advisory
- 2026-07-21 14:06 UTCGHSA enrichment
- 2026-07-21 09:57 UTCVendor advisory
Show 75 moreShow fewer
- 2026-07-21 09:57 UTCGHSA enrichment
- 2026-07-21 05:47 UTCVendor advisory
- 2026-07-21 05:47 UTCGHSA enrichment
- 2026-07-21 01:35 UTCVendor advisory
- 2026-07-21 01:35 UTCGHSA enrichment
- 2026-07-20 21:25 UTCVendor advisory
- 2026-07-20 21:25 UTCGHSA enrichment
- 2026-07-20 17:15 UTCEG score recompute
- 2026-07-20 17:15 UTCVendor advisory
- 2026-07-20 17:15 UTCGHSA enrichment
- 2026-07-20 17:07 UTCEPSS rescore
- 2026-07-20 13:05 UTCVendor advisory
- 2026-07-20 13:05 UTCGHSA enrichment
- 2026-07-20 08:55 UTCVendor advisory
- 2026-07-20 08:55 UTCGHSA enrichment
- 2026-07-20 04:45 UTCVendor advisory
- 2026-07-20 04:45 UTCGHSA enrichment
- 2026-07-20 00:36 UTCVendor advisory
- 2026-07-20 00:36 UTCGHSA enrichment
- 2026-07-19 20:26 UTCVendor advisory
- 2026-07-19 20:26 UTCGHSA enrichment
- 2026-07-19 16:16 UTCEG score recompute
- 2026-07-19 16:16 UTCVendor advisory
- 2026-07-19 16:16 UTCGHSA enrichment
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 12:06 UTCVendor advisory
- 2026-07-19 12:06 UTCGHSA enrichment
- 2026-07-19 07:57 UTCVendor advisory
- 2026-07-19 07:57 UTCGHSA enrichment
- 2026-07-19 03:47 UTCEG score recompute
- 2026-07-19 03:47 UTCVendor advisory
- 2026-07-19 03:47 UTCGHSA enrichment
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-19 02:28 UTCEPSS rescore
- 2026-07-18 23:37 UTCVendor advisory
- 2026-07-18 23:37 UTCGHSA enrichment
- 2026-07-18 19:27 UTCVendor advisory
- 2026-07-18 19:27 UTCGHSA enrichment
- 2026-07-18 15:17 UTCVendor advisory
- 2026-07-18 15:17 UTCGHSA enrichment
- 2026-07-18 11:07 UTCEG score recompute
- 2026-07-18 11:07 UTCVendor advisory
- 2026-07-18 11:07 UTCGHSA enrichment
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-18 06:57 UTCVendor advisory
- 2026-07-18 06:57 UTCGHSA enrichment
- 2026-07-18 02:47 UTCVendor advisory
- 2026-07-18 02:47 UTCGHSA enrichment
- 2026-07-17 22:37 UTCVendor advisory
- 2026-07-17 22:37 UTCGHSA enrichment
- 2026-07-17 18:27 UTCVendor advisory
- 2026-07-17 18:27 UTCGHSA enrichment
- 2026-07-17 14:17 UTCVendor advisory
- 2026-07-17 14:17 UTCGHSA enrichment
- 2026-07-17 10:07 UTCEG score recompute
- 2026-07-17 10:07 UTCVendor advisory
- 2026-07-17 10:07 UTCGHSA enrichment
- 2026-07-17 05:57 UTCVendor advisory
- 2026-07-17 05:57 UTCGHSA enrichment
- 2026-07-17 01:47 UTCVendor advisory
- 2026-07-17 01:47 UTCGHSA enrichment
- 2026-07-16 21:37 UTCVendor advisory
- 2026-07-16 21:37 UTCGHSA enrichment
- 2026-07-16 17:27 UTCVendor advisory
- 2026-07-16 17:27 UTCGHSA enrichment
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-16 13:17 UTCVendor advisory
- 2026-07-16 13:16 UTCGHSA enrichment
- 2026-07-16 09:06 UTCVendor advisory
- 2026-07-16 09:06 UTCGHSA enrichment
- 2026-07-16 04:55 UTCVendor advisory
- 2026-07-16 04:55 UTCGHSA enrichment
- 2026-07-16 00:45 UTCVendor advisory
Publicly available exploits
(2 references)Working exploit code is in the public domain (2 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoC5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201First seen Aug 30, 2025
Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, exploiting WebKit (CVE-2025-24201) and Core Media (CVE-2025-24085) to achieve sandbox escape, kernel-level access, and device bricking. Triggered via iMessage, it enables full compromise with no user interaction.
Open source ↗ - GitHub PoCThe-Maxu/CVE-2025-24201-WebKit-Vulnerability-Detector-PoC-First seen Jul 11, 2025
CVE-2025-24201 WebKit Vulnerability Detector (PoC)
Open source ↗
Frequently asked(6)
What is CVE-2025-24201?
When was CVE-2025-24201 disclosed?
Is CVE-2025-24201 actively exploited?
What is the CVSS score of CVE-2025-24201?
Which products are affected by CVE-2025-24201?
How do I remediate CVE-2025-24201?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2025-24201
Is Your Infrastructure Affected by CVE-2025-24201?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.