CVE-2025-24213
HIGHSafari < 18.5 - Type Confusion leading to Memory Corruption
Title source: llmDescription
This issue was addressed with improved handling of floats. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. A type confusion issue could lead to memory corruption.
References (19)
Core 19
Core References
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/11
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/13
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/2
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/4
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/5
Mailing List
http://seclists.org/fulldisclosure/2025/Apr/8
Mailing List
http://seclists.org/fulldisclosure/2025/May/10
Mailing List
http://seclists.org/fulldisclosure/2025/May/11
Mailing List
http://seclists.org/fulldisclosure/2025/May/13
Mailing List
http://seclists.org/fulldisclosure/2025/May/6
Mailing List
http://seclists.org/fulldisclosure/2025/May/7
Vendor Advisory
https://support.apple.com/en-us/122404
Vendor Advisory
https://support.apple.com/en-us/122405
Vendor Advisory
https://support.apple.com/en-us/122716
Vendor Advisory
https://support.apple.com/en-us/122719
Vendor Advisory
https://support.apple.com/en-us/122720
Vendor Advisory
https://support.apple.com/en-us/122721
Vendor Advisory
https://support.apple.com/en-us/122722
Scores
CVSS v3
7.8
EPSS
0.0039
EPSS Percentile
30.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-843
Status
published
Products (12)
Apple/iOS and iPadOS
< 18.5
apple/ipados
< 17.7.6
Apple/iPadOS
< 17.7.7
apple/iphone_os
< 18.4
Apple/macOS
< 15.5
apple/macos
15.0 - 15.4
apple/safari
< 18.4
Apple/Safari
< 18.5
apple/tvos
< 18.4
Apple/tvOS
< 18.5
... and 2 more
Published
Mar 31, 2025
Tracked Since
Feb 18, 2026