The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 6.5 | Medium | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| Product | Vendor | Version |
|---|---|---|
| iOS and iPadOS | Apple | n/a |
| tvOS | Apple | n/a |
| watchOS | Apple | n/a |
| watchOS | Apple | n/a |
| iOS and iPadOS | Apple | < 2.0.2870_xxx_2.2.12 |