CVE-2018-4278

medium

Description

In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.

References

https://usn.ubuntu.com/3743-1/

https://support.apple.com/HT208938%2C

https://support.apple.com/HT208936%2C

https://support.apple.com/HT208934%2C

https://support.apple.com/HT208933%2C

https://support.apple.com/HT208932

https://security.gentoo.org/glsa/201808-04

https://exchange.xforce.ibmcloud.com/vulnerabilities/146479

http://www.securitytracker.com/id/1041232

Details

Source: Mitre, NVD

Published: 2019-01-11

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Severity: Medium