This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to universal cross site scripting.
Metrics
Affected Vendors & Products
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 26 Sep 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 25 Sep 2024 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | webkitgtk: Processing maliciously crafted web content may lead to universal cross site scripting | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 25 Sep 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple ipados Apple iphone Os Apple macos Apple safari Apple tvos Apple visionos Apple watchos |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple ipados Apple iphone Os Apple macos Apple safari Apple tvos Apple visionos Apple watchos |
|
| Metrics |
cvssV3_1
|
Tue, 17 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Sep 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to universal cross site scripting. | |
| References |
|
Status: PUBLISHED
Assigner: apple
Published: 2024-09-16T23:22:32.092Z
Updated: 2025-03-18T18:46:29.545Z
Reserved: 2024-07-10T17:11:04.711Z
Link: CVE-2024-40857
Updated: 2024-09-17T15:11:42.859Z
Status : Modified
Published: 2024-09-17T00:15:49.537
Modified: 2025-03-18T19:15:43.453
Link: CVE-2024-40857