Medium severity6.5NVD Advisory· Published Sep 17, 2024· Updated Apr 2, 2026
CVE-2024-44187
CVE-2024-44187
Description
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
Affected products
7Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- support.apple.com/en-us/121238nvdRelease NotesVendor Advisory
- support.apple.com/en-us/121240nvdRelease NotesVendor Advisory
- support.apple.com/en-us/121241nvdRelease NotesVendor Advisory
- support.apple.com/en-us/121248nvdRelease NotesVendor Advisory
- support.apple.com/en-us/121249nvdRelease NotesVendor Advisory
- support.apple.com/en-us/121250nvdRelease NotesVendor Advisory
- seclists.org/fulldisclosure/2024/Sep/32nvd
- seclists.org/fulldisclosure/2024/Sep/33nvd
- seclists.org/fulldisclosure/2024/Sep/36nvd
- seclists.org/fulldisclosure/2024/Sep/37nvd
- lists.debian.org/debian-lts-announce/2024/11/msg00019.htmlnvd
News mentions
0No linked articles in our index yet.