CVE-2024-40867

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2024
Last modified:
03/11/2025

Description

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able to break out of Web Content sandbox.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 18.1 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 18.1 (excluding)