The issue was addressed by removing the relevant flags. This issue is fixed in watchOS 11.2, iOS 18.2 and iPadOS 18.2. A system binary could be used to fingerprint a user's Apple Account.
2025-01-27T22:15:12.973
2025-02-04T22:15:41.200
Modified
CVSSv3.1: 9.1 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | ipados | < 18.2 | Yes |
Operating System | apple | iphone_os | < 18.2 | Yes |
Operating System | apple | watchos | < 11.2 | Yes |