An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
2024-03-08T02:15:49.740
2024-12-07T03:11:21.283
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apple | safari | < 17.4 | Yes |
Operating System | apple | ipad_os | < 17.4 | Yes |
Operating System | apple | iphone_os | < 17.4 | Yes |
Operating System | apple | macos | < 14.4 | Yes |
Operating System | apple | tvos | < 17.4 | Yes |
Operating System | apple | watchos | < 10.4 | Yes |
Operating System | fedoraproject | fedora | 38 | Yes |
Operating System | fedoraproject | fedora | 39 | Yes |
Operating System | fedoraproject | fedora | 40 | Yes |
Application | webkitgtk | webkitgtk | < 2.44.0 | Yes |
Application | wpewebkit | wpe_webkit | < 2.44.0 | Yes |