Description
CVE-2025-24167 is a security vulnerability in Apple's Safari browser and operating systems that could allow a download's origin to be incorrectly associated. The issue was addressed by Apple through improved state management in Safari 18.4, iOS 18.4, iPadOS 18.4, and macOS Sequoia 15.4.
Impact
Exploitation of this vulnerability could lead to a download's origin being incorrectly associated, potentially allowing malicious websites to bypass security restrictions. The severity of this issue has been assessed as follows:
CVE-2024-27883
CVE-2024-27883 is a permissions issue within Apple's PackageKit framework that could allow an application to modify protected parts of the file system.
Learn MoreCVE-2024-4558
CVE-2024-4558 is a use-after-free vulnerability in the ANGLE component of Google Chrome. Processing maliciously crafted web content may lead to an unexpected process crash.
Learn MoreCVE-2025-24162
CVE-2025-24162 is a vulnerability in Apple's WebKit engine that could lead to an unexpected process crash when processing maliciously crafted web content. The issue was addressed by Apple through improved state management in the affected systems.
Learn More