Input Validation Flaw in Apple's Safari and iOS Products
CVE-2024-44155
6.5MEDIUM
Key Information:
- Vendor
- Apple
- Vendor
- CVE Published:
- 28 October 2024
Summary
A flaw in input validation related to the handling of custom URL schemes in Apple's Safari browser and various iOS products has been identified. This issue allowed maliciously crafted web content to potentially bypass the iframe sandboxing policy, posing a risk to user data integrity and web application security. Apple has addressed this vulnerability with updates in Safari 18, iOS 17.7.1, iPadOS 17.7.1, macOS Sequoia 15, watchOS 11, iOS 18, and iPadOS 18. Users are encouraged to update their affected products to ensure optimal security.
Affected Version(s)
iOS and iPadOS < 17.7
iOS and iPadOS < 18
macOS < 15
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published