CVE-2025-30434Cross-site Scripting in Apple IOS AND Ipados

Severity
5.0MEDIUMNVD
EPSS
0.1%
top 78.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 31
Latest updateApr 1

Description

The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 1.8 | Impact: 2.7

Affected Packages3 packages

NVDapple/ipados< 18.4
CVEListV5apple/ios_and_ipados< 18.4
NVDapple/iphone_os< 18.4

🔴Vulnerability Details

2
GHSA
GHSA-2xcc-3vq7-mvjp: The issue was addressed with improved input sanitization2025-04-01
CVEList
CVE-2025-30434: The issue was addressed with improved input sanitization2025-03-31

📋Vendor Advisories

1
Apple
CVE-2025-30434: iOS 18.4 and iPadOS 18.42025-03-31
CVE-2025-30434 — Cross-site Scripting in Apple | cvebase