APPLE-SA-03-11-2025-1 Safari 18.3.1
苹果发布Safari 18.3.1安全更新,修复WebKit中的越界写入漏洞,防止恶意网页突破沙盒限制。该漏洞可能被用于针对特定用户的攻击。更新已通过Mac App Store提供。 2025-3-20 12:17:13 Author: seclists.org(查看原文) 阅读量:9 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: Apple Product Security via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 11 Mar 2025 16:12:47 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-03-11-2025-1 Safari 18.3.1

Safari 18.3.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/122285.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

WebKit
Available for: macOS Ventura and macOS Sonoma
Impact: Maliciously crafted web content may be able to break out of Web
Content sandbox. This is a supplementary fix for an attack that was
blocked in iOS 17.2. (Apple is aware of a report that this issue may
have been exploited in an extremely sophisticated attack against
specific targeted individuals on versions of iOS before iOS 17.2.)
Description: An out-of-bounds write issue was addressed with improved
checks to prevent unauthorized actions.
WebKit Bugzilla: 285858
CVE-2025-24201: Apple

Safari 18.3.1 may be obtained from the Mac App Store.

All information is also posted on the Apple Security Releases
web site: https://support.apple.com/100100.

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEsz9altA7uTI+rE/qX+5d1TXaIvoFAmfQry4ACgkQX+5d1TXa
IvoeUQ//d17m1FYNWwedfpt5j2xslU1Z2fNuk8+zQ5JreCU3GbkTRP+jUgYB/JIK
YELtLPTZRjxLBbBBqbSj3IqX7giaC6DY2ujwDH7CItkwj/ET6R75Zbkr8rkgcuo1
GerIfOE2zcGT/kcy/E/UX3vWrFvwGGz3WGuOZNjSmfM3tzhOh7GPKydobfAwAUyG
uI+y1HT6cS8ilqDnks8dTC6KVdCk0x9ht0rZbwQu5escBqhsc7mKls35ZGKD8kDW
A1XICJM/Way568kjrDOcNA9xDUxuVjG1HDMImBWK9BEaC7VdYs9Pa7ZPvtlsZ4VQ
JSlYktJCLR3ZUe23Uu6fFol7LG7iDWEPFd1jHpApKl38eVf7E7THozoJcztXgNXd
iVv4M+0asx7EJd7f5wqWQpEEvAMhQbK/dc811hvA8pFaCVArHWa4xH5XI2EFQZ9M
sK3O6yvXxIKUBqsX+RylqKG2xCKYvSLAPyHYK0Za44evsGV2HhrSUW46P/BmzGo1
l0e/2BUUTlgVeSMefJiUyCVffYtFAKQL5IE3Cx2QQpMB2Qf1RHj/Ih/6YMFJzKOy
c/fYUrSOrrZMlQ4/9R6hRGKK4xruWllxjK2A2bIuh4lcNDyD9hAIw1SWwE1nKijp
2YJG9nUKrOvPCfxupE7V+Bjog3Mzrlrv4mm0NHwu09YG25VK/YM=
=1gat
-----END PGP SIGNATURE-----

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • APPLE-SA-03-11-2025-1 Safari 18.3.1 Apple Product Security via Fulldisclosure (Mar 20)

文章来源: https://seclists.org/fulldisclosure/2025/Mar/2
如有侵权请联系:admin#unsafe.sh