← Back

CVE-2024-44155

nvd nist
Published: Oct 28, 2024Modified: Apr 2, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy.

Affected (5)

5 products
Ipados
Iphone Os
Macos
Safari
Watchos
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 17.7.1
Before 17.7.1
Before 15.0
Before 18.0
Before 11.0

References (6)

Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: product-security@apple.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.