CVE-2025-24158
Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Processing web content on Apple devices may cause a denial-of-service due to a memory handling issue.
Vulnerability
Description CVE-2025-24158 is a memory handling vulnerability in Apple's web content processing. The issue can lead to a denial-of-service when malicious web content is processed. The root cause is improved memory handling, suggesting a memory corruption or similar flaw that causes the application to crash or become unresponsive.
Exploitation
An attacker can exploit this vulnerability by convincing a user to view a specially crafted webpage. No special privileges or network access are required beyond the ability to deliver web content. The vulnerability affects multiple Apple platforms including Safari, iOS, iPadOS, macOS, tvOS, and visionOS.
Impact
Successful exploitation results in a denial-of-service condition, potentially causing Safari or the entire system to crash or become unresponsive. While the impact is limited to availability, it could disrupt user productivity or service availability.
Mitigation
Apple has addressed this issue in security updates released on January 27, 2025. The fixes are included in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, and visionOS 2.3 [1][2][3][4]. Users should update their devices to the latest operating system versions to protect against this vulnerability.
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
51cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <18.3
- (no CPE)range: <18.3
- osv-coords43 versionspkg:rpm/almalinux/webkit2gtk3pkg:rpm/almalinux/webkit2gtk3-develpkg:rpm/almalinux/webkit2gtk3-jscpkg:rpm/almalinux/webkit2gtk3-jsc-develpkg:rpm/opensuse/webkit2gtk3&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/webkit2gtk3-soup2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/webkit2gtk4&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP6pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/webkit2gtk3&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/webkit2gtk3-soup2&distro=SUSE%20Manager%20Server%204.3pkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP6pkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/webkit2gtk4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5
< 2.46.6-1.el8_10+ 42 more
- (no CPE)range: < 2.46.6-1.el8_10
- (no CPE)range: < 2.46.6-1.el8_10
- (no CPE)range: < 2.46.6-1.el8_10
- (no CPE)range: < 2.46.6-1.el8_10
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-150200.133.1
- (no CPE)range: < 2.46.6-150200.133.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-4.28.1
- (no CPE)range: < 2.46.6-150200.133.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150200.133.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-4.28.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-150600.12.27.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
- (no CPE)range: < 2.46.6-150400.4.106.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- support.apple.com/en-us/122066nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122068nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122071nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122072nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122073nvdRelease NotesVendor Advisory
- support.apple.com/en-us/122074nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2025/Jan/13nvd
- seclists.org/fulldisclosure/2025/Jan/15nvd
- seclists.org/fulldisclosure/2025/Jan/18nvd
- seclists.org/fulldisclosure/2025/Jan/20nvd
- lists.debian.org/debian-lts-announce/2025/02/msg00014.htmlnvd
News mentions
0No linked articles in our index yet.