vulnerability
Oracle Linux: CVE-2025-24201: ELSA-2025-2863: webkit2gtk3 security update (IMPORTANT) (Multiple Advisories)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:H/Au:N/C:C/I:C/A:C) | Mar 11, 2025 | Mar 18, 2025 | Apr 7, 2025 |
Severity
8
CVSS
(AV:N/AC:H/Au:N/C:C/I:C/A:C)
Published
Mar 11, 2025
Added
Mar 18, 2025
Modified
Apr 7, 2025
Description
An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in visionOS 2.3.2, iOS 18.3.2 and iPadOS 18.3.2, macOS Sequoia 15.3.2, Safari 18.3.1. Maliciously crafted web content may be able to break out of Web Content sandbox. This is a supplementary fix for an attack that was blocked in iOS 17.2. (Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2.).
An out-of-bounds write flaw was found in WebKit. Maliciously crafted web content may be able to break out of the Web Content sandbox and perform unauthorized actions.
An out-of-bounds write flaw was found in WebKit. Maliciously crafted web content may be able to break out of the Web Content sandbox and perform unauthorized actions.
Solution(s)
oracle-linux-upgrade-webkit2gtk3oracle-linux-upgrade-webkit2gtk3-develoracle-linux-upgrade-webkit2gtk3-jscoracle-linux-upgrade-webkit2gtk3-jsc-devel

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.