Vulnerability · NVD
CVE-2025-24150
HIGH 8.8
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
2.90%
above median
percentile 85.7%
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.