REDHAT-BUG-2344621: Medium severity macOS vulnerability
The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.3 - Compensating control
Implement improved access restrictions to the file system to prevent maliciously crafted webpages from fingerprinting users (as described in the fix).
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2344621?
The severity of REDHAT-BUG-2344621 is high due to the potential for user fingerprinting through malicious webpages.
How do I fix REDHAT-BUG-2344621?
To fix REDHAT-BUG-2344621, users should update to macOS Sequoia 15.3, Safari 18.3, iOS 18.3, iPadOS 18.3, or visionOS 2.3.
What software is affected by REDHAT-BUG-2344621?
REDHAT-BUG-2344621 affects macOS Sequoia up to version 15.2, Safari up to version 18.2, iOS up to version 18.2, iPadOS up to version 18.2, and visionOS up to version 2.2.
What are the risks associated with REDHAT-BUG-2344621?
The risks associated with REDHAT-BUG-2344621 include unauthorized user fingerprinting and potential privacy breaches.
Is there a workaround for REDHAT-BUG-2344621?
There is no known workaround for REDHAT-BUG-2344621; updating the affected software is recommended.