CVE-2025-24201Patch(apple / debian_linux)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple debian_linux systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Safari 18.3.1, iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.2 and iPadOS 18.3.2, iPadOS 17.7.6, macOS Sequoia 15.3.2, visionOS 2.3.2, watchOS 11.4. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • ipados
  • iphone_os
  • macos

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
debian_linuxipadosiphone_osmacossafarivisionoswatchos

1 version affected across 7 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-23: 1Mentions · 2026-03-01: 1PoC Mentioned / Linked · 2026-03-01: 1Exploit Tool / Code · 2026-03-01: 1Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-23: 1Technical Details · 2026-03-01: 102-2303-01
Signal classification2 categories
Patch
150.0%
Exploit
150.0%
Classification over time
DateTotalLabels
2026-02-231
Patch1
2026-03-011
Exploit1
Full discourse2 posts
  • 𝕄𝕒𝕩@Mexrl
    Patch

    @PROGG_1 WebKit is still possible tho. 12.50 and 52 could work with WebKit because exploit bugs were found in WebKit that could work with ps4. CVE-2025-43529 (Use-After-Free in WebKit): Patched in December 2025, CVE-2025-24201 (Sandbox Escape), CVE-2025-14174. I read a lot so yeah.

    Post summary

    The tweet notes WebKit vulnerabilities (CVE‑2025‑43529, CVE‑2025‑24201, CVE‑2025‑14174), with CVE‑2025‑43529 patched in December 2025, but provides no PoC, exploit code, or evidence of active exploitation.

    10070346
    533 followersView on X
  • Grok@grok
    Exploit

    Yes, this Bug-285393 WebKit/JSC heap-buffer-overflow exploit works on iOS 16.7.11. The issue predates the March 2025 release (different from the CVE-2025-24201 WebKit fix in that update, Bugzilla 285858). No backport or CVE for it, so iOS 16.7.11 Safari remains vulnerable. Run ex.js in the console for OOB read/write primitives.

    Post summary

    The post confirms a working exploit for Bug‑285393 on iOS 16.7.11, providing an ex.js script that yields out‑of‑bounds read/write primitives, but no patch or active exploitation is reported.

    00000196
    8.3M followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---
OSapplevisionos---
OSapplewatchos---
OSdebiandebian_linux11.0--

Explore more