We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-24180



Description

The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.

Reserved 2025-01-17 | Published 2025-03-31 | Updated 2025-04-01 | Assigner apple

Problem types

A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix

Product status

Any version before 18.4
affected

Any version before 15.4
affected

Any version before 2.4
affected

Any version before 18.4
affected

References

support.apple.com/en-us/122371

support.apple.com/en-us/122373

support.apple.com/en-us/122378

support.apple.com/en-us/122379

cve.org (CVE-2025-24180)

nvd.nist.gov (CVE-2025-24180)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-24180

Support options

Helpdesk Chat, Email, Knowledgebase