The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.4 and iPadOS 18.4. Processing a maliciously crafted file may lead to a cross site scripting attack.
2025-03-31T23:15:25.600
2025-11-03T22:18:45.327
Modified
CVSSv3.1: 5.0 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | apple | ipados | < 18.4 | Yes |
| Operating System | apple | iphone_os | < 18.4 | Yes |