The issue was addressed with improved UI handling. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, Safari 17.4. A malicious website may exfiltrate audio data cross-origin.
2024-03-08T02:15:48.663
2024-12-06T02:54:01.530
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | safari | < 17.4 | Yes |
Operating System | apple | ipad_os | < 17.4 | Yes |
Operating System | apple | iphone_os | < 17.4 | Yes |
Operating System | apple | macos | < 14.4 | Yes |
Operating System | apple | tvos | < 17.4 | Yes |
Operating System | apple | visionos | < 1.1 | Yes |
Operating System | apple | watchos | < 10.4 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |
Application | webkitgtk | webkitgtk | < 2.44.0 | Yes |
Application | wpewebkit | wpe_webkit | < 2.44.0 | Yes |