CVE-2024-23280
08.03.2024, 02:15
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
| Vendor | Product | Version |
|---|---|---|
| apple | safari | 𝑥 < 17.4 |
| apple | ipad_os | 𝑥 < 17.4 |
| apple | iphone_os | 𝑥 < 17.4 |
| apple | macos | 14.0 ≤ 𝑥 < 14.4 |
| apple | tvos | 𝑥 < 17.4 |
| apple | watchos | 𝑥 < 10.4 |
| webkitgtk | webkitgtk | 𝑥 < 2.44.0 |
| wpewebkit | wpe_webkit | 𝑥 < 2.44.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| webkit2gtk |
| ||||||||||||||||
| wpewebkit |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| webkitgtk |
| ||||||||||||
| webkit2gtk |
| ||||||||||||
| qtwebkit-source |
| ||||||||||||
| wpewebkit |
| ||||||||||||
| qtwebkit-opensource-src |
|
References