CVE-2025-24803PoC(opensecurity / mobile_security_framework)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework. According to Apple's documentation for bundle ID's, it must contain only alphanumeric characters (A–Z, a–z, and 0–9), hyphens (-), and periods (.). However, an attacker can manually modify this value in the `Info.plist` file and add special characters to the `<key>CFBundleIdentifier</key>` value. The `dynamic_analysis.html` file does not sanitize the received bundle value from Corellium and as a result, it is possible to break the HTML context and achieve Stored XSS. This issue has been addressed in version 4.3.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mobile_security_framework

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
mobile_security_framework

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-19: 1PoC Mentioned / Linked · 2026-03-19: 1Technical Details · 2026-03-19: 103-19
Signal classification1 categories
PoC
1100.0%
Full discourse1 post
  • warp_polaris@warp_polaris
    PoC

    CVE-2025-24803 *Figure 1. Unsanitized bundle* &lt;img src="test" onerror="alert('Hello PT')"&gt; *Figure 2. Example of the modified Bundle Identifier* • Zip the modified IPA file. *Listing 2. ![TEST](javascript:alert("Test2")) Zipping the file* ``` zip -r xss.ipa Payload/ ```

    Post summary

    The post provides a clear proof‑of‑concept demonstrating a cross‑site scripting vulnerability in iOS IPA bundles for CVE‑2025‑24803, but does not detail an exploit tool or note active exploitation.

    0000098
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensecuritymobile_security_framework4.3.0--

Explore more