CVE-2025-24158: The issue was addressed with improved memory handling.
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service.
Security readout for executives and security teams
Plain-English summary
CVE-2025-24158 is an Apple web-content handling flaw that can crash or disrupt affected software. A user must process malicious or problematic web content. Apple fixed it in January 2025 platform updates. The main business risk is availability disruption, not confirmed data theft or device takeover.
Executive priority
Treat as routine but timely Apple patching. Prioritize managed endpoints and mobile fleets that browse external content. Escalate only where availability disruption of Apple devices would materially affect operations.
Technical view
Apple describes this as improved memory handling for processing web content, leading to denial-of-service. Fixed versions are Safari 18.3, iOS/iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, and watchOS 11.3. CVSS 3.1 is 6.5: network reachable, low complexity, no privileges, user interaction required, availability impact high.
Likely exposure
Organizations with Apple endpoints, mobile devices, managed browsers, Apple TVs, Vision Pro devices, or Apple Watches below the fixed versions may be exposed when users encounter crafted web content.
Exploitation context
The provided sources do not report active exploitation, and this CVE is not listed as KEV in the supplied data. Exploitation requires user interaction with web content and is described as denial-of-service only.
Researcher notes
The record has limited technical detail beyond memory handling and denial-of-service while processing web content. CWE-79 is listed in the supplied data, but Apple’s description does not provide enough detail to infer a specific bug class or exploitation path.
Mitigation direction
Update Safari to 18.3 where applicable.
Update iOS and iPadOS devices to 18.3 or later.
Update macOS Sequoia systems to 15.3 or later.
Update tvOS, visionOS, and watchOS to Apple’s fixed releases.
Check Apple advisories for product-specific update applicability.
Validation and detection
Inventory Apple assets and record OS, browser, and device versions.
Confirm Safari 18.3 or later on managed Macs where applicable.
Confirm iOS and iPadOS 18.3 or later on mobile fleets.
Confirm macOS Sequoia 15.3 or later on managed Macs.
Review MDM compliance reports for remaining vulnerable versions.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-79: User-session and phishing behavior lookup
Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.