PT-2024-31073 · Apple · Safari+4

Jacob Braun

·

Published

2024-12-11

·

Updated

2024-12-18

·

CVE-2024-44246

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions macOS Sequoia versions prior to 15.2 iOS versions prior to 18.2 iPadOS versions prior to 18.2 Safari versions prior to 18.2 iPadOS versions prior to 17.7.3
Description The issue was addressed with improved routing of Safari-originated requests. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.
Recommendations For macOS Sequoia versions prior to 15.2, update to macOS Sequoia 15.2 to resolve the issue. For iOS versions prior to 18.2, update to iOS 18.2 to resolve the issue. For iPadOS versions prior to 18.2, update to iPadOS 18.2 to resolve the issue. For Safari versions prior to 18.2, update to Safari 18.2 to resolve the issue. For iPadOS versions prior to 17.7.3, update to iPadOS 17.7.3 to resolve the issue.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-44246

Affected Products

Apple Macos
Safari
Ios
Ipados
Macos Sequoia