CVE-2024-44187: Input Validation
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
Other sources
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.
— Debian
A malicious website may exfiltrate data cross-origin. A cross- origin issue existed with “iframe” elements. This was addressed with improved tracking of security origins.
— Red Hat
Accessibility. This issue was addressed by restricting options offered on a locked device.
— Apple
Accessibility. This issue was addressed through improved state management.
— Apple
Accessibility. This issue was addressed with improved data protection.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-44171
- CVE-2024-40850
- CVE-2024-27880
- CVE-2024-44176
- CVE-2024-44169
- CVE-2024-44191
- CVE-2024-54560
- CVE-2024-44198
- CVE-2024-44183
- CVE-2024-44155
- CVE-2024-44144
- CVE-2024-44170
- CVE-2024-54467
- CVE-2024-44192
- CVE-2024-40857
- CVE-2024-44187
- CVE-2024-44126
- CVE-2024-40825
- CVE-2024-27876
- CVE-2024-40855
- CVE-2024-54469
- CVE-2024-44165
- CVE-2023-5841
- CVE-2024-44167
- CVE-2024-40790
- CVE-2024-40856
- CVE-2024-44202
- CVE-2024-40866
- CVE-2024-40840
- CVE-2024-40830
- CVE-2024-40852
- CVE-2024-27874
- CVE-2024-27869
- CVE-2024-44124
- CVE-2024-44131
- CVE-2024-44122
- CVE-2024-40791
- CVE-2024-44147
- CVE-2024-44217
- CVE-2024-40826
- CVE-2024-44127
- CVE-2024-40863
- CVE-2024-44123
- CVE-2024-44145
- CVE-2024-44179
- CVE-2024-40853
- CVE-2024-44139
- CVE-2024-44180
- CVE-2024-54558
- CVE-2024-44184
- CVE-2024-27879
- CVE-2024-44227
- CVE-2024-44129
- CVE-2024-44153
- CVE-2024-44188
- CVE-2024-40792
- CVE-2024-44130
- CVE-2024-44182
- CVE-2024-44154
- CVE-2024-40845
- CVE-2024-40846
- CVE-2024-44164
- CVE-2024-40837
- CVE-2024-40847
- CVE-2024-40848
- CVE-2024-44168
- CVE-2024-27860
- CVE-2024-27861
- CVE-2024-40841
- CVE-2024-27795
- CVE-2024-44135
- CVE-2024-44132
- CVE-2024-44128
- CVE-2024-44151
- CVE-2024-44172
- CVE-2024-27875
- CVE-2024-44146
- CVE-2024-27849
- CVE-2023-4504
- CVE-2024-44148
- CVE-2024-44177
- CVE-2024-54463
- CVE-2024-40831
- CVE-2024-40861
- CVE-2024-44160
- CVE-2024-44161
- CVE-2024-44175
- CVE-2024-54473
- CVE-2024-44181
- CVE-2024-27858
- CVE-2024-40838
- CVE-2024-44186
- CVE-2024-39894
- CVE-2024-44178
- CVE-2024-44149
- CVE-2024-40797
- CVE-2024-44125
- CVE-2024-44163
- CVE-2024-44203
- CVE-2024-44137
- CVE-2024-44174
- CVE-2024-40801
- CVE-2024-44158
- CVE-2024-40844
- CVE-2024-40860
- CVE-2024-44152
- CVE-2024-44166
- CVE-2024-44190
- CVE-2024-44133
- CVE-2024-40859
- CVE-2024-41957
- CVE-2024-54546
- CVE-2024-40770
- CVE-2024-23237
- CVE-2024-44134
- CVE-2024-44189
- CVE-2024-44208
- CVE-2024-40842
- CVE-2024-40843
Frequently Asked Questions
What is the severity of CVE-2024-44187?
CVE-2024-44187 is classified as a cross-origin vulnerability that may allow data exfiltration from compromised browsers.
How do I fix CVE-2024-44187?
To fix CVE-2024-44187, update to Safari 18, iOS 18, iPadOS 18, macOS Sequoia 15, watchOS 11, tvOS 18, or visionOS 2.
Which versions of Safari are affected by CVE-2024-44187?
Safari versions prior to 18 are affected by CVE-2024-44187.
Can CVE-2024-44187 be exploited in mobile operating systems?
Yes, CVE-2024-44187 can be exploited in mobile operating systems running affected versions of iOS and iPadOS.
Is CVE-2024-44187 present in webkit2gtk package versions?
CVE-2024-44187 can affect webkit2gtk versions prior to 2.46.0 as well as wpewebkit versions prior to 2.46.2.