An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
| Version | Score | Severity | Vector String |
|---|---|---|---|
| 3.1 | 7.5 | High | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Product | Vendor | Version |
|---|---|---|
| iOS and iPadOS | Apple | WCN3980 |
| Safari | Apple | < 10.0.22631.2861 |
| macOS | Apple | < 2.4.46-lp151.10.12.1 |
| watchOS | Apple | <= 4.5 |
| Safari | Apple | n/a |
| watchOS | Apple | S7x and prior |