Critical severity9.6NVD Advisory· Published Oct 28, 2024· Updated Jun 17, 2026
CVE-2024-40867
CVE-2024-40867
Description
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <18.1
- (no CPE)range: before 18.1
- Range: before 18.1
- Range: 0
Patches
Vulnerability mechanics
References
2- support.apple.com/en-us/121563nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2024/Oct/9nvd
News mentions
0No linked articles in our index yet.