Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-40867


A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.


Published

2024-10-28T21:15:04.937

Last Modified

2025-11-03T22:17:11.350

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple ipados < 18.1 Yes
Operating System apple iphone_os < 18.1 Yes

References