cbcvebase.
CVE-2025-24128
published 2025-01-27

CVE-2025-24128: The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious…

PriorityP418medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.56%
43.0th percentile
The issue was addressed by adding additional logic. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Visiting a malicious website may lead to address bar spoofing.

Affected

8 ranges
VendorProductVersion rangeFixed in
appleios_18.3_and_ipados
appleios_and_ipados< 18.318.3
appleipados< 18.318.3
appleiphone_os< 18.318.3
applemacos< 15.315.3
applemacos_sequoia
applesafari< 18.318.3
applesafari
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.