CVE-2025-24143

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*

History

04 Feb 2025, 22:15

Type Values Removed Values Added
CWE CWE-862

30 Jan 2025, 18:03

Type Values Removed Values Added
CPE cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://support.apple.com/en-us/122066 - () https://support.apple.com/en-us/122066 - Release Notes
References () https://support.apple.com/en-us/122068 - () https://support.apple.com/en-us/122068 - Release Notes
References () https://support.apple.com/en-us/122073 - () https://support.apple.com/en-us/122073 - Release Notes
References () https://support.apple.com/en-us/122074 - () https://support.apple.com/en-us/122074 - Release Notes
Summary
  • (es) El problema se solucionó mejorando las restricciones de acceso al archivo sistema. Este problema se solucionó en macOS Sequoia 15.3, Safari 18.3, iOS 18.3 y iPadOS 18.3, visionOS 2.3. Una página web malintencionada manipulado puede tomar la huella digital del usuario.
First Time Apple
Apple safari
Apple macos
Apple ipados
Apple visionos

27 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-27 22:15

Updated : 2025-02-04 22:15


NVD link : CVE-2025-24143

Mitre link : CVE-2025-24143

CVE.ORG link : CVE-2025-24143


JSON object : View

Products Affected

apple

  • ipados
  • safari
  • macos
  • visionos
CWE
NVD-CWE-noinfo CWE-862

Missing Authorization