CVE-2025-24150
published 2025-01-27CVE-2025-24150: A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.90%
85.4th percentile
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.3_and_ipados | — | — |
| apple | ios_and_ipados | < 18.3 | 18.3 |
| apple | ipados | < 18.3 | 18.3 |
| apple | iphone_os | < 18.3 | 18.3 |
| apple | macos | < 15.3 | 15.3 |
| apple | macos_sequoia | — | — |
| apple | safari | < 18.3 | 18.3 |
| apple | safari | — | — |
| debian | webkit2gtk | < webkit2gtk 2.46.6-1~deb12u1 (bookworm) | webkit2gtk 2.46.6-1~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.46.6-1~deb12u1 (bookworm) | webkit2gtk 2.46.6-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2025-02-20
CVE-2025-24158 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Copying a URL from Web Inspector may lead to command injection
vendor_redhat·2025-01-27·CVSS 8.8
CVE-2025-24150 [HIGH] CWE-77 webkitgtk: Copying a URL from Web Inspector may lead to command injection
webkitgtk: Copying a URL from Web Inspector may lead to command injection
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.
A flaw was found in WebKitGTK. Copying a URL from Web Inspector may lead to command injection due to improper file handling.
Statement: To exploit this flaw, an attacker needs to trick a user into performing unlikely actions, such as enabling and opening the web inspector in an application and loading malicious web content into it. For this reason, this flaw has been rated with a Moderate severity.
Mitigation: Do not process or load untrusted web content with WebKitGTK.
Package: webkitgtk (Red Hat Enterpris
Apple
CVE-2025-24150: macOS Sequoia 15.3
vendor_apple·2025-01-27·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150: macOS Sequoia 15.3
Apple Security Update: About the security content of macOS Sequoia 15.3
Product: macOS Sequoia
Version: 15.3
CVE: CVE-2025-24150
Component: WebKit Web Inspector
Impact: Copying a URL from Web Inspector may lead to command injection
Description: A privacy issue was addressed with improved handling of files.
Apple
CVE-2025-24150: Safari 18.3
vendor_apple·2025-01-27·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150: Safari 18.3
Apple Security Update: About the security content of Safari 18.3
Product: Safari
Version: 18.3
CVE: CVE-2025-24150
Component: WebKit Web Inspector
Impact: Copying a URL from Web Inspector may lead to command injection
Description: A privacy issue was addressed with improved handling of files.
Apple
CVE-2025-24150: iOS 18.3 and iPadOS 18.3
vendor_apple·2025-01-27·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150: iOS 18.3 and iPadOS 18.3
Apple Security Update: About the security content of iOS 18.3 and iPadOS 18.3
Product: iOS 18.3 and iPadOS
Version: 18.3
CVE: CVE-2025-24150
Component: WebKit Web Inspector
Impact: Copying a URL from Web Inspector may lead to command injection
Description: A privacy issue was addressed with improved handling of files.
Debian
CVE-2025-24150: webkit2gtk - A privacy issue was addressed with improved handling of files. This issue is fix...
vendor_debian·2025·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150: webkit2gtk - A privacy issue was addressed with improved handling of files. This issue is fix...
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.
Scope: local
bookworm: resolved (fixed in 2.46.6-1~deb12u1)
bullseye: resolved (fixed in 2.46.6-1~deb11u1)
forky: resolved (fixed in 2.46.6-1)
sid: resolved (fixed in 2.46.6-1)
trixie: resolved (fixed in 2.46.6-1)
GHSA
GHSA-qmjg-q5x7-48p2: A privacy issue was addressed with improved handling of files
ghsa_unreviewed·2025-01-28
CVE-2025-24150 [HIGH] CWE-77 GHSA-qmjg-q5x7-48p2: A privacy issue was addressed with improved handling of files
A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.
OSV
CVE-2025-24150: A privacy issue was addressed with improved handling of files
osv·2025-01-27·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150: A privacy issue was addressed with improved handling of files
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.
OSV
CVE-2025-24150: A privacy issue was addressed with improved handling of files
osv·2025-01-27·CVSS 8.8
CVE-2025-24150 [HIGH] CVE-2025-24150: A privacy issue was addressed with improved handling of files
A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.
No detection rules found.
No public exploits indexed.
https://support.apple.com/en-us/122066https://support.apple.com/en-us/122068https://support.apple.com/en-us/122074http://seclists.org/fulldisclosure/2025/Jan/13http://seclists.org/fulldisclosure/2025/Jan/15http://seclists.org/fulldisclosure/2025/Jan/20https://lists.debian.org/debian-lts-announce/2025/02/msg00014.html
2025-01-27
Published