#VU106320 Security features bypass in macOS - CVE-2025-24180
Published: April 1, 2025
macOS
Apple Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists in Authentication Services due to insufficient input validation. A remote attacker can trick the victim into visiting a specially crafted website that is able to claim WebAuthn credentials from another website that shares a registrable suffix.