An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
Version | Score | Severity | Vector String |
---|---|---|---|
3.1 | 7.5 | High | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Product | Vendor | Version |
---|---|---|
tvOS | Apple | < fb824a99e148ff272a53d71d84122728b5f00992 |
iOS and iPadOS | Apple | n/a |
Safari | Apple | < 16.4.4 |
macOS | Apple | < 16.5.4 |
watchOS | Apple | <= 2.0 |