PT-2024-31020 · Apple+9 · Visionos+16

Narendra Bhati

·

Published

2024-09-16

·

Updated

2025-11-25

·

CVE-2024-44187

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Safari version 18 visionOS version 2 watchOS version 11 macOS Sequoia version 15 iOS version 18 iPadOS version 18 tvOS version 18
Description A cross-origin issue existed with iframe elements, allowing a malicious website to exfiltrate data cross-origin. This issue was addressed with improved tracking of security origins.
Recommendations For Safari version 18, no additional action is required as the issue is fixed. For visionOS version 2, no additional action is required as the issue is fixed. For watchOS version 11, no additional action is required as the issue is fixed. For macOS Sequoia version 15, no additional action is required as the issue is fixed. For iOS version 18, no additional action is required as the issue is fixed. For iPadOS version 18, no additional action is required as the issue is fixed. For tvOS version 18, no additional action is required as the issue is fixed. As a temporary workaround for older versions, consider disabling the use of iframe elements until a patch is available.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:8180
ALSA-2024:9553
ALSA-2024:9636
BDU:2025-04167
CESA-2024_9636
CVE-2024-44187
DLA-3961-1
DSA-5792-1
INFSA-2024_8180
INFSA-2024_9553
INFSA-2024_9636
MGASA-2025-0313
OPENSUSE-SU-2024_3752-1
OPENSUSE-SU-2024_3869-1
OPENSUSE-SU-2024_4084-1
OPENSUSE-SU-2025_0043-1
OPENSUSE-SU-2025_0096-1
RHSA-2024:8180
RHSA-2024:9553
RHSA-2024:9636
RHSA-2024_8180
RHSA-2024_9553
RHSA-2024_9636
RHSA-2025:10364
RLSA-2024:8180
RLSA-2024:9636
SUSE-SU-2024:3751-1
SUSE-SU-2024:3752-1
SUSE-SU-2024:3869-1
SUSE-SU-2024:3870-1
SUSE-SU-2024:4084-1
SUSE-SU-2025:0043-1
SUSE-SU-2025:0096-1
SUSE-SU-2025:0104-1
USN-7079-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Suse
Ubuntu
Ios
Ipados
Macos Sequoia
Tvos
Visionos
Watchos