A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
2024-10-28T21:15:04.937
2025-11-03T22:17:11.350
Modified
CVSSv3.1: 9.6 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | apple | ipados | < 18.1 | Yes |
| Operating System | apple | iphone_os | < 18.1 | Yes |