CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-24150: A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3....

Description

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.

Classification

CVE ID: CVE-2025-24150

Affected Products

Vendor: Apple

Product: macOS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 29.54% (scored less or equal to compared to others)

EPSS Date: 2025-02-25 (when was this score calculated)

References

https://support.apple.com/en-us/122068
https://support.apple.com/en-us/122074
https://support.apple.com/en-us/122066

Timeline