cbcvebase.
CVE-2025-24150
published 2025-01-27

CVE-2025-24150: A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.

Affected

10 ranges
VendorProductVersion rangeFixed in
appleios_18.3_and_ipados
appleios_and_ipados< 18.318.3
appleipados< 18.318.3
appleiphone_os< 18.318.3
applemacos< 15.315.3
applemacos_sequoia
applesafari< 18.318.3
applesafari
debianwebkit2gtk< webkit2gtk 2.46.6-1~deb12u1 (bookworm)webkit2gtk 2.46.6-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.46.6-1~deb12u1 (bookworm)webkit2gtk 2.46.6-1~deb12u1 (bookworm)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH