File System Access Vulnerability in Apple's macOS, iOS, iPadOS, Safari, and visionOS
CVE-2025-24143

6.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
27 January 2025

Summary

A vulnerability exists in Apple's macOS, iOS, iPadOS, Safari, and visionOS products due to inadequate access restrictions in the file system. This flaw may allow a maliciously crafted webpage to exploit the user's privacy by fingerprinting their device. Apple has addressed this issue in the latest updates, enhancing file system access controls to mitigate potential threats. Users are encouraged to update their devices to the latest versions provided.

Affected Version(s)

iOS and iPadOS < 18.3

macOS < 15.3

Safari < 18.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.