CVE-2025-24208
published 2025-03-31CVE-2025-24208: A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.53%
41.9th percentile
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.4_and_ipados | — | — |
| apple | ios_and_ipados | < 18.4 | 18.4 |
| apple | ipados | < 18.4 | 18.4 |
| apple | iphone_os | < 18.4 | 18.4 |
| apple | safari | < 18.4 | 18.4 |
| apple | safari | — | — |
| debian | webkit2gtk | < webkit2gtk 2.48.1-2~deb12u1 (bookworm) | webkit2gtk 2.48.1-2~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.48.1-2~deb12u1 (bookworm) | webkit2gtk 2.48.1-2~deb12u1 (bookworm) |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
WebKitGTK vulnerabilities
vendor_ubuntu·2025-04-14
CVE-2025-24208 WebKitGTK vulnerabilities
Title: WebKitGTK vulnerabilities
Summary: Several security issues were fixed in WebKitGTK.
Several security issues were discovered in the WebKitGTK Web and JavaScript
engines. If a user were tricked into viewing a malicious website, a remote
attacker could exploit a variety of issues related to web browser security,
including cross-site scripting attacks, denial of service attacks, and
arbitrary code execution.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any applications
that use WebKitGTK, such as Epiphany, to make all the necessary changes.
Red Hat
webkitgtk: Loading a malicious iframe may lead to a cross-site scripting attack
vendor_redhat·2025-04-07·CVSS 6.1
CVE-2025-24208 [MEDIUM] CWE-79 webkitgtk: Loading a malicious iframe may lead to a cross-site scripting attack
webkitgtk: Loading a malicious iframe may lead to a cross-site scripting attack
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
A flaw was found in WebKitGTK. Loading a malicious iframe can cause a cross-site scripting attack due to permissions issues.
Statement: To exploit this flaw, an attacker needs to trick a user into processing or loading malicious web content.
Mitigation: Do not process or load untrusted web content with WebKitGTK.
In Red Hat Enterprise Linux 7, the following packages require WebKitGTK4: evolution-data-server, glade, gnome-boxes, gnome-initial-setup, gnome-online-accounts, gnome-shell, shotwell, sushi and yelp.
This
Apple
CVE-2025-24208: Safari 18.4
vendor_apple·2025-03-31·CVSS 6.1
CVE-2025-24208 [MEDIUM] CVE-2025-24208: Safari 18.4
Apple Security Update: About the security content of Safari 18.4
Product: Safari
Version: 18.4
CVE: CVE-2025-24208
Component: WebKit
Impact: Loading a malicious iframe may lead to a cross-site scripting attack
Description: A permissions issue was addressed with additional restrictions.
Apple
CVE-2025-24208: iOS 18.4 and iPadOS 18.4
vendor_apple·2025-03-31·CVSS 6.1
CVE-2025-24208 [MEDIUM] CVE-2025-24208: iOS 18.4 and iPadOS 18.4
Apple Security Update: About the security content of iOS 18.4 and iPadOS 18.4
Product: iOS 18.4 and iPadOS
Version: 18.4
CVE: CVE-2025-24208
Component: WebKit
Impact: Loading a malicious iframe may lead to a cross-site scripting attack
Description: A permissions issue was addressed with additional restrictions.
Debian
CVE-2025-24208: webkit2gtk - A permissions issue was addressed with additional restrictions. This issue is fi...
vendor_debian·2025·CVSS 6.1
CVE-2025-24208 [MEDIUM] CVE-2025-24208: webkit2gtk - A permissions issue was addressed with additional restrictions. This issue is fi...
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
Scope: local
bookworm: resolved (fixed in 2.48.1-2~deb12u1)
bullseye: resolved (fixed in 2.48.3-1~deb11u1)
forky: resolved (fixed in 2.48.1-1)
sid: resolved (fixed in 2.48.1-1)
trixie: resolved (fixed in 2.48.1-1)
GHSA
GHSA-vwcg-r7w2-v8qc: A permissions issue was addressed with additional restrictions
ghsa_unreviewed·2025-04-01
CVE-2025-24208 [MEDIUM] CWE-79 GHSA-vwcg-r7w2-v8qc: A permissions issue was addressed with additional restrictions
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
OSV
CVE-2025-24208: A permissions issue was addressed with additional restrictions
osv·2025-03-31·CVSS 6.1
CVE-2025-24208 [MEDIUM] CVE-2025-24208: A permissions issue was addressed with additional restrictions
A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.
No detection rules found.
No public exploits indexed.
2025-03-31
Published