An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "17.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "17.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "17.4"
}
]
},
{
"events": [
{
"introduced": "14.0"
},
{
"fixed": "14.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "17.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "10.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "40"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.44.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.44.0"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23280.json"