An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
2024-03-08T02:15:49.740
2025-11-04T19:16:46.943
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | apple | safari | < 17.4 | Yes |
| Operating System | apple | ipad_os | < 17.4 | Yes |
| Operating System | apple | iphone_os | < 17.4 | Yes |
| Operating System | apple | macos | < 14.4 | Yes |
| Operating System | apple | tvos | < 17.4 | Yes |
| Operating System | apple | watchos | < 10.4 | Yes |
| Operating System | fedoraproject | fedora | 38 | Yes |
| Operating System | fedoraproject | fedora | 39 | Yes |
| Operating System | fedoraproject | fedora | 40 | Yes |
| Application | webkitgtk | webkitgtk | < 2.44.0 | Yes |
| Application | wpewebkit | wpe_webkit | < 2.44.0 | Yes |