vulnerability

Amazon Linux AMI 2: CVE-2025-24208: Security patch for webkitgtk4 (ALAS-2025-2869)

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Mar 31, 2025
Added
May 30, 2025
Modified
May 30, 2025

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4. Loading a malicious iframe may lead to a cross-site scripting attack.

Solutions

amazon-linux-ami-2-upgrade-webkitgtk4amazon-linux-ami-2-upgrade-webkitgtk4-debuginfoamazon-linux-ami-2-upgrade-webkitgtk4-develamazon-linux-ami-2-upgrade-webkitgtk4-jscamazon-linux-ami-2-upgrade-webkitgtk4-jsc-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.