CVE-2025-24201
published 2025-03-11CVE-2025-24201: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS…
PriorityP191critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-04-03
Exploited in the wild
EPSS
4.24%
89.9th percentile
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.8.4_and_ipados | — | — |
| apple | ios_16.7.11_and_ipados | — | — |
| apple | ios_18.3.2_and_ipados | — | — |
| apple | ios_and_ipados | < 15.8.4 | 15.8.4 |
| apple | ios_and_ipados | < 16.7.11 | 16.7.11 |
| apple | ios_and_ipados | < 18.3.2 | 18.3.2 |
| apple | ipados | < 17.7.6 | 17.7.6 |
| apple | ipados | — | — |
| apple | ipados | >= 15.8 < 15.8.4 | 15.8.4 |
| apple | ipados | >= 16.7 < 16.7.11 | 16.7.11 |
| apple | ipados | >= 17.0 < 17.7.6 | 17.7.6 |
| apple | ipados | >= 18.0 < 18.3.2 | 18.3.2 |
| apple | iphone_os | >= 15.8 < 15.8.4 | 15.8.4 |
| apple | iphone_os | >= 16.7 < 16.7.11 | 16.7.11 |
| apple | iphone_os | >= 17.0 < 18.3.2 | 18.3.2 |
| apple | macos | < 15.3.2 | 15.3.2 |
| apple | macos | >= 15.0 < 15.3.2 | 15.3.2 |
| apple | macos_sequoia | — | — |
| apple | safari | < 18.3.1 | 18.3.1 |
| apple | safari | — | — |
| apple | visionos | < 2.3.2 | 2.3.2 |
| apple | visionos | — | — |
| apple | watchos | < 11.4 | 11.4 |
| apple | watchos | — | — |
| chromium | chromium | >= 0 < 134.0.6998.88-1~deb12u1 | 134.0.6998.88-1~deb12u1 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2025-24201 is an out-of-bounds write in WebKit (GPU/Web Content sandbox escape); look for maliciously crafted web content triggering sandbox breakout from the WebKit Web Content process ↗
- →The vulnerability is specifically classified as an out-of-bounds write in the GPU component on Mac within Chromium/WebKit; monitor GPU process activity originating from web content rendering ↗
- →Active in-the-wild exploitation confirmed; treat any unexplained WebKit Web Content sandbox escape on iOS versions prior to iOS 17.2 as a high-confidence indicator of this attack chain ↗
- →This is a supplementary fix for an attack vector that was partially blocked in iOS 17.2; investigate devices running iOS < 17.2 for signs of prior exploitation, as the original attack predates the supplementary patch ↗
- →Google confirmed exploit existence in the wild; Microsoft Edge (Chromium-based) versions prior to 134.0.3124.62 (based on Chromium 134.0.6998.89) are vulnerable — flag unpatched Edge versions in enterprise environments ↗
- ·Exploitation has been described as 'extremely sophisticated' and highly targeted; mass exploitation is not currently reported, but patching is still strongly advised for all users ↗
- ·The affected component is WebKit (Web Content sandbox / GPU process); the vulnerability manifests only when processing maliciously crafted web content, not through other attack surfaces ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
osv10.0CRITICAL
vulncheck10.0CRITICAL
cisa10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_msrc10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-24201: watchOS 11.4
vendor_apple·2025-04-01·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: watchOS 11.4
Apple Security Update: About the security content of watchOS 11.4
Product: watchOS
Version: 11.4
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2025-03-31
CVE-2025-24201 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Apple
CVE-2025-24201: iOS 15.8.4 and iPadOS 15.8.4
vendor_apple·2025-03-31·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: iOS 15.8.4 and iPadOS 15.8.4
Apple Security Update: About the security content of iOS 15.8.4 and iPadOS 15.8.4
Product: iOS 15.8.4 and iPadOS
Version: 15.8.4
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2025-24201: iPadOS 17.7.6
vendor_apple·2025-03-31·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: iPadOS 17.7.6
Apple Security Update: About the security content of iPadOS 17.7.6
Product: iPadOS
Version: 17.7.6
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2025-24201: iOS 16.7.11 and iPadOS 16.7.11
vendor_apple·2025-03-31·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: iOS 16.7.11 and iPadOS 16.7.11
Apple Security Update: About the security content of iOS 16.7.11 and iPadOS 16.7.11
Product: iOS 16.7.11 and iPadOS
Version: 16.7.11
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
CISA
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
cisa·2025-03-13·CVSS 10.0
CVE-2025-24201 [CRITICAL] CWE-787 Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Vulnerability: Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Affected: Apple Multiple Products
Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/122281 ; https://support.apple.com/en-us/122283 ; https://support.apple.com/en-us/122284 ; https://sup
Microsoft
Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac
vendor_msrc·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac
Chromium: CVE-2025-24201 Out of bounds write in GPU on Mac
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
Google is aware of reports that an exploit for CVE-2025-24201 exists in the wild.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
134.0.3124.62
3/12//2025
134.0.6998.89
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edg
Apple
CVE-2025-24201: Safari 18.3.1
vendor_apple·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: Safari 18.3.1
Apple Security Update: About the security content of Safari 18.3.1
Product: Safari
Version: 18.3.1
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2025-24201: visionOS 2.3.2
vendor_apple·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: visionOS 2.3.2
Apple Security Update: About the security content of visionOS 2.3.2
Product: visionOS
Version: 2.3.2
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Apple
CVE-2025-24201: macOS Sequoia 15.3.2
vendor_apple·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: macOS Sequoia 15.3.2
Apple Security Update: About the security content of macOS Sequoia 15.3.2
Product: macOS Sequoia
Version: 15.3.2
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Red Hat
webkitgtk: out-of-bounds write vulnerability
vendor_redhat·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CWE-787 webkitgtk: out-of-bounds write vulnerability
webkitgtk: out-of-bounds write vulnerability
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
A flaw was found in WebKitGTK. Processing malicious web content can trigger an out-of-bounds write due to improper checks to
Apple
CVE-2025-24201: iOS 18.3.2 and iPadOS 18.3.2
vendor_apple·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: iOS 18.3.2 and iPadOS 18.3.2
Apple Security Update: About the security content of iOS 18.3.2 and iPadOS 18.3.2
Product: iOS 18.3.2 and iPadOS
Version: 18.3.2
CVE: CVE-2025-24201
Component: WebKit
Impact: Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions.
Debian
CVE-2025-24201: chromium - An out-of-bounds write issue was addressed with improved checks to prevent unaut...
vendor_debian·2025·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: chromium - An out-of-bounds write issue was addressed with improved checks to prevent unaut...
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
Scope: local
bookworm: resolved (fixed in 134.0.6998.88-1~deb12u1)
OSV
CVE-2025-24201: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions
osv·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1, watchOS 11.4, iPadOS 17.7.6, iOS 16.7.11 and iPadOS 16.7.11, iOS 15.8.4 and iPadOS 15.8.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
GHSA
GHSA-2j99-5q75-3f57: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions
ghsa_unreviewed·2025-03-11
CVE-2025-24201 [HIGH] CWE-787 GHSA-2j99-5q75-3f57: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
OSV
CVE-2025-24201: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions
osv·2025-03-11·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201: An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
VulnCheck
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
vulncheck·2025·CVSS 10.0
CVE-2025-24201 [CRITICAL] CWE-787 Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability
Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/en-us/122281;
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
blogs_bleepingcomputer·2025-12-12·CVSS 8.8
CVE-2025-43529 [HIGH] Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
## Lawrence Abrams
CVE-2025-43529 is a WebKit use-after-free remote code execution flaw that can be exploited by processing maliciously crafted web content. Apple says the flaw was discovered by Google’s Threat Analysis Group.
CVE-2025-14174 is a WebKit memory corruption flaw that could lead to memory corruption. Apple says the flaw was discovered by both Apple and Google’s Threat Analysis Group.
Devices impacted by both flaws include:
iPhone 11 and later
iPad Pro 12.9-inch (3rd generation and later)
iPad Pro 11-inch (1st generation and later)
iPad Air (3rd generation and later)
iPad (8th generation and later)
iPad mini (5th generation and later)
Apple has fixed the flaws in iOS 26.2 and iPadOS 26.2, iOS 18.7
Bleepingcomputer
Apple backports zero-day patches to older iPhones and iPads
blogs_bleepingcomputer·2025-09-16·CVSS 10.0
[CRITICAL] Apple backports zero-day patches to older iPhones and iPads
## Apple backports zero-day patches to older iPhones and iPads
## Sergiu Gatlan
An out-of-bounds write occurs when attackers supply maliciously crafted input to a program that causes it to write data outside the allocated memory buffer, potentially triggering crashes, corrupting data, or even allowing remote code execution.
Apple has now addressed this zero-day flaw in iOS 15.8.5 / 16.7.12, as well as iPadOS 15.8.5 / 16.7.12, with improved bounds checks.
"Processing a malicious image file may result in memory corruption. An out-of-bounds write issue was addressed with improved bounds checking," the company said in Monday advisories .
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals."
The lis
Bleepingcomputer
Apple fixes new zero-day flaw exploited in targeted attacks
blogs_bleepingcomputer·2025-08-20·CVSS 10.0
[CRITICAL] Apple fixes new zero-day flaw exploited in targeted attacks
## Apple fixes new zero-day flaw exploited in targeted attacks
## Sergiu Gatlan
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals," the company revealed in security advisories issued on Wednesday.
"An out-of-bounds write issue was addressed with improved bounds checking. Processing a malicious image file may result in memory corruption."
Apple has addressed this issue with improved bounds checking to prevent exploitation in iOS 18.6.2 and iPadOS 18.6.2 , iPadOS 17.7.10 , macOS Sequoia 15.6.1 , macOS Sonoma 14.7.8 , and macOS Ventura 13.7.8 .
The complete list of devices impacted by this zero-day vulnerability is extensive, as the bug impacts both older and newer models, including:
iPhone XS a
Bleepingcomputer
Apple patches security flaw exploited in Chrome zero-day attacks
blogs_bleepingcomputer·2025-07-30·CVSS 8.8
CVE-2025-6558 [HIGH] Apple patches security flaw exploited in Chrome zero-day attacks
## Apple patches security flaw exploited in Chrome zero-day attacks
## Sergiu Gatlan
Vlad Stolyarov and Clément Lecigne of Google's Threat Analysis Group (TAG), a team of security experts dedicated to defending Google customers against state-sponsored attacks, discovered CVE-2025-6558 in June and reported it to the Google Chrome team, who patched it on July 15 and tagged it as actively exploited in attacks.
While Google has yet to provide further information on these attacks, Google TAG frequently discovers zero-day flaws exploited by government-sponsored threat actors in targeted campaigns aimed at deploying spyware on devices of high-risk individuals, including dissidents, opposition politicians, and journalists.
On Tuesday, Apple released WebKit security updates to address the CVE-2
Bleepingcomputer
Apple fixes two zero-days exploited in targeted iPhone attacks
blogs_bleepingcomputer·2025-04-16·CVSS 10.0
CVE-2025-31200 [CRITICAL] Apple fixes two zero-days exploited in targeted iPhone attacks
## Apple fixes two zero-days exploited in targeted iPhone attacks
## Lawrence Abrams
The CVE-2025-31200 flaw in CoreAudio was discovered by Apple and the Google Threat Analysis team. It can be exploited by processing an audio stream in a maliciously crafted media file to execute remote code on the device.
The company also fixed CVE-2025-31201, which Apple discovered. It is a bug in RPAC that allows attackers with read or write access to bypass Pointer Authentication (PAC), an iOS security feature that helps protect against memory vulnerabilities.
Apple has not shared further details on how the flaws were exploited in attacks. BleepingComputer contacted Apple and Google with questions about flaws but has not received a response.
Both vulnerabilities were fixed in iOS 18.4.1 , iPadOS 18
Checkpoint
7th April – Threat Intelligence Report
blogs_checkpoint·2025-04-07
CVE-2024-20439 7th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th April, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The second-largest bar association in the US, The State Bar of Texas, has experienced a ransomware attack that resulted in unauthorized access to its network, exposing sensitive member information including full names and legal case documents. The INC ransomware gang claimed responsibility for the attack and has already leaked
Bleepingcomputer
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
blogs_bleepingcomputer·2025-03-11·CVSS 7.8
CVE-2025-24201 [HIGH] Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
## Sergiu Gatlan
Apple said attackers can exploit the CVE-2025-24201 vulnerability using maliciously crafted web content to break out of the Web Content sandbox.
The company has fixed this out-of-bounds write issue with improved checks to prevent unauthorized actions in iOS 18.3.2, iPadOS 18.3.2 , macOS Sequoia 15.3.2 , visionOS 2.3.2 , and Safari 18.3.1 .
The list of devices impacted by this zero-day is quite extensive, as the bug affects older and newer models, including:
iPhone XS and later,
iPad Pro 13-inch, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 7th generation and later, and iPad mini 5th generation and later
Macs
Bugzilla
CVE-2025-24201 webkitgtk: out-of-bounds write vulnerability
bugzilla·2025-03-13·CVSS 10.0
CVE-2025-24201 [CRITICAL] CVE-2025-24201 webkitgtk: out-of-bounds write vulnerability
CVE-2025-24201 webkitgtk: out-of-bounds write vulnerability
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:2863 https://access.redhat.com/errata/RHSA-2025:2863
---
This issue has been addressed
https://support.apple.com/en-us/122281https://support.apple.com/en-us/122283https://support.apple.com/en-us/122284https://support.apple.com/en-us/122285https://support.apple.com/en-us/122345https://support.apple.com/en-us/122346https://support.apple.com/en-us/122372https://support.apple.com/en-us/122376http://seclists.org/fulldisclosure/2025/Apr/16http://seclists.org/fulldisclosure/2025/Apr/7http://seclists.org/fulldisclosure/2025/Jun/19http://seclists.org/fulldisclosure/2025/Mar/2http://seclists.org/fulldisclosure/2025/Mar/3http://seclists.org/fulldisclosure/2025/Mar/4http://seclists.org/fulldisclosure/2025/Mar/5http://seclists.org/fulldisclosure/2025/Oct/1http://seclists.org/fulldisclosure/2025/Oct/31https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201https://github.com/cisagov/vulnrichment/issues/194https://lists.debian.org/debian-lts-announce/2025/06/msg00016.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24201
2025-03-11
Published
2025-03-13
Added to CISA KEV
Exploited in the wild