Apple WebAuthn Credential Theft Vulnerability in Safari, iOS, iPadOS, visionOS, and macOS

Vulnerability

A vulnerability exists in Safari, iOS, iPadOS, visionOS, and macOS that allows a malicious website to claim WebAuthn credentials from another site sharing a registrable suffix. This issue arises from inadequate input validation, enabling potential credential theft across different platforms.

Impact

Exploitation of this vulnerability could lead to unauthorized access to WebAuthn credentials, allowing for credential theft between websites.

Remediation

This vulnerability has been fixed in Safari 18.4, iOS 18.4, iPadOS 18.4, visionOS 2.4, and macOS Sequoia 15.4.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.