CVE-2024-27838

medium

Description

The issue was addressed by adding additional logic. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.

References

https://support.apple.com/en-us/HT214108

https://support.apple.com/en-us/HT214106

https://support.apple.com/en-us/HT214104

https://support.apple.com/en-us/HT214103

https://support.apple.com/en-us/HT214102

https://support.apple.com/en-us/HT214101

https://support.apple.com/en-us/HT214100

http://seclists.org/fulldisclosure/2024/Jun/5

Details

Source: Mitre, NVD

Published: 2024-06-10

Updated: 2024-07-03

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Severity: High

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity: Medium