First published: Thu Mar 20 2025(Updated: )
A cookie management issue was addressed with improved state management. This issue is fixed in watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <11 | |
macOS | <15 | |
Safari | <18 | |
visionOS | <2 | |
Apple iOS and iPadOS | <18 | |
Apple iOS, iPadOS, and macOS | <18 | |
tvOS | <18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2353872 is classified as high due to the potential for data exfiltration across origins.
To fix REDHAT-BUG-2353872, update to the latest versions of watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18, iPadOS 18, or tvOS 18.
Products affected by REDHAT-BUG-2353872 include watchOS, macOS Sequoia, Safari, visionOS, iOS, iPadOS, and tvOS.
REDHAT-BUG-2353872 enables a cross-origin data exfiltration attack through improper cookie management.
There currently is no documented workaround for REDHAT-BUG-2353872; updating to fixed versions is the recommended action.