Security features bypass in macOS - CVE-2025-24180
Published: April 1, 2025
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists in Authentication Services due to insufficient input validation. A remote attacker can trick the victim into visiting a specially crafted website that is able to claim WebAuthn credentials from another website that shares a registrable suffix.
Affected software
visionOS
watchOS
iPadOS
Apple iOS
Apple Safari
How to mitigate CVE-2025-24180
visionOS - update to 2.4
watchOS - update to 11.4
Apple Safari - update to 18.4
iPadOS - update to 18.4 22E240
Apple iOS - update to 18.4 22E240