Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-31205

Опубликовано: 12 мая 2025
Источник: debian
EPSS Низкий

Описание

The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.48.2-1package
wpewebkitfixed2.48.2-1package
wpewebkitignoredbookwormpackage
wpewebkitignoredbullseyepackage

Примечания

  • https://webkitgtk.org/security/WSA-2025-0004.html

  • https://project-zero.issues.chromium.org/issues/408172161

EPSS

Процентиль: 4%
0.0002
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.

CVSS3: 6.5
redhat
6 месяцев назад

The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.

CVSS3: 6.5
nvd
6 месяцев назад

The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.

CVSS3: 6.5
github
6 месяцев назад

The issue was addressed with improved checks. This issue is fixed in watchOS 11.5, tvOS 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, visionOS 2.5, Safari 18.5. A malicious website may exfiltrate data cross-origin.

CVSS3: 6.5
fstec
7 месяцев назад

Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit, связанная с подделкой межсайтовых запросов, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 4%
0.0002
Низкий