CVE-2024-23280
08.03.2024, 02:15
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
Vendor | Product | Version |
---|---|---|
apple | safari | 𝑥 < 17.4 |
apple | ipad_os | 𝑥 < 17.4 |
apple | iphone_os | 𝑥 < 17.4 |
apple | macos | 14.0 ≤ 𝑥 < 14.4 |
apple | tvos | 𝑥 < 17.4 |
apple | watchos | 𝑥 < 10.4 |
webkitgtk | webkitgtk | 𝑥 < 2.44.0 |
wpewebkit | wpe_webkit | 𝑥 < 2.44.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
webkit2gtk |
| ||||||||||||
wpewebkit |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
qtwebkit-opensource-src |
| ||||||||||||
qtwebkit-source |
| ||||||||||||
webkit2gtk |
| ||||||||||||
webkitgtk |
| ||||||||||||
wpewebkit |
|
References