VulnerabilityModified
CVE-2025-30427
A use-after-free issue was addressed with improved memory management.
MEDIUM 4.3EPSS 0.80%
Does this matter?
Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.
Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing maliciously crafted web content may lead to an unexpected Safari crash.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- EPSS
- 0.80% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- apple/safari · apple/ipados · apple/iphone os · apple/macos · apple/tvos · apple/visionos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/122371Vendor Advisory
- https://support.apple.com/en-us/122372Vendor Advisory
- https://support.apple.com/en-us/122373Vendor Advisory
- https://support.apple.com/en-us/122376
- https://support.apple.com/en-us/122377Vendor Advisory
- https://support.apple.com/en-us/122378Vendor Advisory
- https://support.apple.com/en-us/122379Vendor Advisory
- http://seclists.org/fulldisclosure/2025/Apr/11
- http://seclists.org/fulldisclosure/2025/Apr/12
- http://seclists.org/fulldisclosure/2025/Apr/13
- http://seclists.org/fulldisclosure/2025/Apr/2
- http://seclists.org/fulldisclosure/2025/Apr/4
- http://seclists.org/fulldisclosure/2025/Apr/5
- http://seclists.org/fulldisclosure/2025/Apr/8
- https://lists.debian.org/debian-lts-announce/2025/06/msg00016.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.