Cross-Site Scripting Vulnerability in Safari and iOS Products by Apple
CVE-2025-24208

Currently unrated

Key Information:

Vendor
Apple
Vendor
CVE Published:
31 March 2025

Summary

A permissions issue in Safari, iOS, and iPadOS has been found that could allow a malicious iframe to trigger a cross-site scripting attack. Apple has addressed this issue in the latest updates, ensuring additional restrictions are in place to enhance the security of its products. Users are strongly encouraged to update their devices to the latest versions to mitigate potential threats.

Affected Version(s)

iOS and iPadOS < 18.4

Safari < 18.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.