CVE-2025-24180 Information
Apr 03, 2025
cve
Description
The issue was addressed with improved input validation. This issue is fixed in Safari 18.4 visionOS 2.4 iOS 18.4 and iPadOS 18.4 macOS Sequoia 15.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.
Reference
https://support.apple.com/en-us/122371 https://support.apple.com/en-us/122373 https://support.apple.com/en-us/122378 https://support.apple.com/en-us/122379
Share on: