CVE-2024-40782

EUVD-2024-38623
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing maliciously crafted web content may lead to an unexpected process crash.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
applesafari
𝑥
< 17.6
appleipados
𝑥
< 16.7.9
appleipados
17.0 ≤
𝑥
< 17.6
appleiphone_os
𝑥
< 16.7.9
appleiphone_os
17.0 ≤
𝑥
< 17.6
applemacos
14.0 ≤
𝑥
< 14.6
appletvos
𝑥
< 17.6
applevisionos
𝑥
< 1.3
applewatchos
𝑥
< 10.6
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
applesafari
𝑥
< 17.6
ADP
appleios
𝑥
< 17.6
ADP
appleipad_os
𝑥
< 17.6
ADP
appleios
𝑥
< 16.7
ADP
appleipad_os
𝑥
< 16.7
ADP
applewatch_os
𝑥
< 10.6
ADP
applemac_os
𝑥
< 14.6
ADP
applevisionos
𝑥
< 1.3
ADP
appletv_os
𝑥
< 17.6
ADP