Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-24192

CVE-2025-24192: Apple Safari Information Disclosure Flaw

CVE-2025-24192 is an information disclosure vulnerability in Apple Safari caused by a script imports issue. Visiting malicious websites may leak sensitive data. This article covers technical details, affected versions, and patches.

Published:

CVE-2025-24192 Overview

CVE-2025-24192 is an information disclosure vulnerability in Apple's WebKit-based Safari browser and multiple Apple operating systems. The flaw stems from improper isolation of script imports, which allows a malicious website to leak sensitive data across security boundaries when visited. Apple addressed the issue with improved isolation in Safari 18.4, iOS 18.4, iPadOS 18.4, macOS Sequoia 15.4, and visionOS 2.4.

The vulnerability requires user interaction, specifically visiting a crafted webpage, but requires no authentication. Successful exploitation results in exposure of sensitive information handled within the browser context.

Critical Impact

Visiting a crafted website may leak sensitive data from other origins or contexts due to insufficient isolation of script imports in WebKit.

Affected Products

  • Apple Safari (prior to 18.4)
  • Apple iOS and iPadOS (prior to 18.4)
  • Apple macOS Sequoia (prior to 15.4)
  • Apple visionOS (prior to 2.4)

Discovery Timeline

  • 2025-03-31 - CVE-2025-24192 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-24192

Vulnerability Analysis

The vulnerability resides in how WebKit processes script imports. Script imports in modern browsers allow JavaScript modules to load and execute code from external sources. When isolation between imported scripts and their execution contexts is insufficient, data intended to remain private within one origin can become accessible to another.

An attacker exploits this by hosting a malicious webpage that leverages script import behavior to observe or extract sensitive content. The attack executes entirely in the browser, requiring only that a victim visit the attacker-controlled URL. No privileges are needed, and no additional local access is required.

Apple classifies the fix as improved isolation, indicating the root cause involves cross-context data exposure rather than memory corruption. The CWE remains unassigned (NVD-CWE-noinfo), consistent with Apple's limited public disclosure practices.

Root Cause

The root cause is inadequate isolation between script import execution contexts within WebKit. Data that should have been segmented across origin or module boundaries could be observed by scripts operating in a different trust context, resulting in unauthorized information exposure.

Attack Vector

The attack vector is network-based, delivered through a webpage. The victim must visit the malicious site for exploitation to succeed. No further interaction beyond page navigation is documented. Because Safari and WebKit are the default browser and rendering engine across Apple platforms, exposure spans desktop, mobile, and mixed-reality devices.

No public proof-of-concept, exploit code, or in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2025-24192

Indicators of Compromise

  • Safari or WebKit-embedded application versions older than the patched builds (Safari 18.4, iOS/iPadOS 18.4, macOS 15.4, visionOS 2.4) on managed devices.
  • Browser telemetry showing navigation to unknown domains followed by anomalous outbound requests carrying data fragments from other origins.
  • User reports of unexpected data appearing in third-party web content.

Detection Strategies

  • Inventory Apple devices and identify systems running Safari, iOS, iPadOS, macOS, or visionOS versions below the fixed releases.
  • Correlate web proxy logs with threat intelligence to flag visits to domains hosting suspicious cross-origin script import behavior.
  • Monitor MDM compliance dashboards for devices that have not received the March 2025 Apple security update.

Monitoring Recommendations

  • Track OS and Safari version distribution across the fleet through MDM reporting.
  • Alert on prolonged deferral of Apple software updates on user endpoints.
  • Review web gateway logs for outbound requests to newly registered or low-reputation domains from Safari user agents.

How to Mitigate CVE-2025-24192

Immediate Actions Required

  • Update Safari to version 18.4 on macOS systems that support standalone Safari updates.
  • Upgrade iPhone and iPad devices to iOS 18.4 or iPadOS 18.4.
  • Upgrade macOS Sequoia systems to 15.4.
  • Upgrade Apple Vision Pro devices to visionOS 2.4.
  • Enforce patch compliance through MDM policies and remove exceptions for delayed updates.

Patch Information

Apple released fixes across the affected platforms and documented them in Apple Support Document #122371, Apple Support Document #122373, Apple Support Document #122378, and Apple Support Document #122379. The fix improves isolation of script imports within WebKit to prevent cross-context data leakage.

Workarounds

  • Avoid using Safari and WebKit-based applications for sensitive browsing sessions on unpatched devices until updates are applied.
  • Restrict browsing on unpatched devices to trusted domains through enterprise web filtering.
  • Configure MDM policies to defer non-essential browsing capabilities for out-of-date devices until patched.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.