First published: Mon Sep 16 2024(Updated: )
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.
Credit: product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <18.0 | |
Apple iPadOS | <18.0 | |
Apple iPhone OS | <18.0 | |
Apple macOS | <15.0 | |
Apple tvOS | <18.0 | |
Apple visionOS | <2.0 | |
Apple watchOS | <11.0 | |
debian/webkit2gtk | <=2.44.2-1~deb11u1<=2.44.3-1~deb11u1<=2.44.2-1~deb12u1 | 2.46.0-2~deb12u1 2.46.2-1 2.46.3-1 |
debian/wpewebkit | <=2.38.6-1~deb11u1<=2.38.6-1 | 2.46.2-1 2.46.3-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44187 is classified as a cross-origin vulnerability that may allow data exfiltration from compromised browsers.
To fix CVE-2024-44187, update to Safari 18, iOS 18, iPadOS 18, macOS Sequoia 15, watchOS 11, tvOS 18, or visionOS 2.
Safari versions prior to 18 are affected by CVE-2024-44187.
Yes, CVE-2024-44187 can be exploited in mobile operating systems running affected versions of iOS and iPadOS.
CVE-2024-44187 can affect webkit2gtk versions prior to 2.46.0 as well as wpewebkit versions prior to 2.46.2.