CVE-2024-44155: Input Validation
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, iOS 18 and iPadOS 18, macOS Sequoia 15, watchOS 11. Maliciously crafted web content may violate iframe sandboxing policy.
Other sources
Accessibility. The issue was addressed with improved authentication.
— Apple
Accessibility. This issue was addressed by restricting options offered on a locked device.
— Apple
Accessibility. This issue was addressed through improved state management.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44171
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44169
- CVE-2024-44191
- CVE-2024-54560
- CVE-2024-44198
- CVE-2024-44183
- CVE-2024-44155
- CVE-2024-44144
- CVE-2024-44170
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-44187
- CVE-2024-44202
- CVE-2024-40866
- CVE-2024-40840
- CVE-2024-40830
- CVE-2024-40852
- CVE-2024-44126
- CVE-2024-27874
- CVE-2024-27876
- CVE-2024-27869
- CVE-2024-44124
- CVE-2024-54469
- CVE-2024-44131
- CVE-2024-44165
- CVE-2024-44122
- CVE-2024-40791
- CVE-2023-5841
- CVE-2024-44147
- CVE-2024-44167
- CVE-2024-44217
- CVE-2024-40826
- CVE-2024-44127
- CVE-2024-40863
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-40853
- CVE-2024-44139
- CVE-2024-44180
- CVE-2024-54558
- CVE-2024-44184
- CVE-2024-27879
- CVE-2024-44227
- CVE-2024-40856
- CVE-2024-44129
- CVE-2024-44153
- CVE-2024-44188
- CVE-2024-40792
- CVE-2024-40825
- CVE-2024-44130
- CVE-2024-44182
- CVE-2024-44154
- CVE-2024-40845
- CVE-2024-40846
- CVE-2024-44164
- CVE-2024-40837
- CVE-2024-40847
- CVE-2024-40848
- CVE-2024-44168
- CVE-2024-27860
- CVE-2024-27861
- CVE-2024-40841
- CVE-2024-27795
- CVE-2024-44135
- CVE-2024-44132
- CVE-2024-44128
- CVE-2024-44151
- CVE-2024-44172
- CVE-2024-27875
- CVE-2024-44146
- CVE-2024-27849
- CVE-2023-4504
- CVE-2024-40855
- CVE-2024-44148
- CVE-2024-44177
- CVE-2024-54463
- CVE-2024-40831
- CVE-2024-40861
- CVE-2024-44160
- CVE-2024-44161
- CVE-2024-44175
- CVE-2024-54473
- CVE-2024-44181
- CVE-2024-27858
- CVE-2024-40838
- CVE-2024-44186
- CVE-2024-39894
- CVE-2024-44178
- CVE-2024-44149
- CVE-2024-40797
- CVE-2024-44125
- CVE-2024-44163
- CVE-2024-44203
- CVE-2024-44137
- CVE-2024-44174
- CVE-2024-40801
- CVE-2024-44158
- CVE-2024-40844
- CVE-2024-40860
- CVE-2024-44152
- CVE-2024-44166
- CVE-2024-44190
- CVE-2024-44133
- CVE-2024-40859
- CVE-2024-41957
- CVE-2024-54546
- CVE-2024-40770
- CVE-2024-23237
- CVE-2024-44134
- CVE-2024-44189
- CVE-2024-44208
- CVE-2024-40842
- CVE-2024-40843
- CVE-2024-44274
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-44282
- CVE-2024-40854
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44239
- CVE-2024-44258
- CVE-2024-44252
- CVE-2024-44259
- CVE-2024-44218
- CVE-2024-54538
- CVE-2024-44269
- CVE-2024-54470
- CVE-2024-44278
- CVE-2024-44261
- CVE-2024-44296
Frequently Asked Questions
What is the severity of CVE-2024-44155?
CVE-2024-44155 is classified as a high-severity vulnerability due to its potential to violate iframe sandboxing policies.
How do I fix CVE-2024-44155?
To fix CVE-2024-44155, users should update to Safari 18, iOS 17.7.1, iPadOS 17.7.1, macOS Sequoia 15, watchOS 11, or any later versions.
What impact does CVE-2024-44155 have on users?
CVE-2024-44155 can allow maliciously crafted web content to bypass security policies, potentially exposing users to security risks.
Which software versions are affected by CVE-2024-44155?
CVE-2024-44155 affects Safari versions prior to 18.0, iPadOS versions prior to 17.7.1, iPhone OS versions prior to 17.7.1, macOS versions prior to 15.0, and watchOS versions prior to 11.0.
Is there a known exploit for CVE-2024-44155?
As of now, there is no public disclosure of an active exploit specifically targeting CVE-2024-44155.