CVE-2024-44155 Information

Description

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18 iOS 17.7.1 and iPadOS 17.7.1 macOS Sequoia 15 watchOS 11 iOS 18 and iPadOS 18. Maliciously crafted web content may violate iframe sandboxing policy.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Reference

https://support.apple.com/en-us/121238 https://support.apple.com/en-us/121567 https://support.apple.com/en-us/121250 https://support.apple.com/en-us/121240 https://support.apple.com/en-us/121241

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: