logo

Apple Drops Another WebKit Zero-Day Bug

ID: 88c1aff0-cc64-5f07-b394-90c7c48dbfed

STIX ID: report--88c1aff0-cc64-5f07-b394-90c7c48dbfed

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-12

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Apple released emergency fixes for CVE-2025-24201, an out-of-bounds write in the WebKit engine used by Safari and other apps across iOS, iPadOS, macOS, and visionOS; the flaw enables sandbox escape and could lead to arbitrary code execution and full device compromise. Apple says the bug has been exploited in an "extremely sophisticated" targeted attack, prompting updates and mitigation guidance while researchers note exploitation requires advanced skills and is likely part of targeted, high-resource operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.