Description
The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service.
Published: 2025-01-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A memory handling flaw in WebKitGTK can cause a denial of service when rendering web content. The weakness involves excessive memory allocation, as indicated by CWE-770, and an input validation failure, CWE-79, which together allow an attacker to crash the target process. The impact is a crash of the WebKit component, potentially disrupting user applications that rely on web rendering, but no direct data compromise is described.

Affected Systems

Apple Safari, iOS, iPadOS, macOS Sequoia, tvOS, visionOS, and watchOS are affected. The vulnerability is fixed in Safari 18.3, iOS 18.3, iPadOS 18.3, macOS 15.3, tvOS 18.3, visionOS 2.3, and watchOS 11.3. Red Hat Enterprise Linux 8, 9 and RHEL ELS 7 are also listed as affected via the CPEs but the description does not specify impact on those platforms.

Risk and Exploitability

The CVSS score of 6.5 classifies this as a moderate severity vulnerability. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of this analysis, and it is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote—an attacker could embed malicious content within a web page that a user or application renders, potentially triggering the memory overflow and causing a crash. No specific prerequisites beyond the ability to deliver such content are mentioned in the entry.

Generated by OpenCVE AI on April 28, 2026 at 04:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Safari, iOS, iPadOS, macOS, tvOS, visionOS, and watchOS to the minimum versions where the issue is fixed (18.3 or later for Apple operating systems).
  • For systems without the updated version, restrict or disable WebKit-based rendering of external content if possible to limit exposure.
  • Keep all software up to date by monitoring vendor advisories and applying future patches promptly.

Generated by OpenCVE AI on April 28, 2026 at 04:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4051-1 webkit2gtk security update
Debian DSA Debian DSA DSA-5865-1 webkit2gtk security update
EUVD EUVD EUVD-2025-3660 The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.
Ubuntu USN Ubuntu USN USN-7279-1 WebKitGTK vulnerabilities
History

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service. The issue was addressed with improved memory handling. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. Processing web content may lead to a denial-of-service.

Mon, 03 Nov 2025 21:30:00 +0000


Mon, 07 Jul 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els

Fri, 25 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Sat, 05 Apr 2025 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:enterprise_linux:9

Sat, 22 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 12 Mar 2025 07:00:00 +0000

Type Values Removed Values Added
References

Tue, 04 Mar 2025 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Mon, 03 Mar 2025 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple ipados
Apple iphone Os
Apple macos
Apple safari
Apple tvos
Apple visionos
Apple watchos

Wed, 12 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
Title webkitgtk: Processing web content may lead to a denial-of-service
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 28 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jan 2025 22:00:00 +0000

Type Values Removed Values Added
Description The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:14:16.675Z

Reserved: 2025-01-17T00:00:44.987Z

Link: CVE-2025-24158

cve-icon Vulnrichment

Updated: 2025-11-03T21:04:44.674Z

cve-icon NVD

Status : Modified

Published: 2025-01-27T22:15:19.800

Modified: 2026-04-02T19:19:09.373

Link: CVE-2025-24158

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-27T21:45:49Z

Links: CVE-2025-24158 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T04:15:16Z