CVE-2024-27850

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/06/2024
Last modified:
02/04/2026

Description

This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* 17.5 (excluding)
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* 17.5 (excluding)
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* 17.5 (excluding)
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* 14.0 (including) 14.5 (excluding)
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* 1.2 (excluding)