CVE-2024-27850

medium

Description

This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5, iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to fingerprint the user.

References

https://support.apple.com/en-us/HT214108

https://support.apple.com/en-us/HT214106

https://support.apple.com/en-us/HT214103

https://support.apple.com/en-us/HT214101

http://seclists.org/fulldisclosure/2024/Jun/5

Details

Source: Mitre, NVD

Published: 2024-06-10

Updated: 2024-07-03

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

Severity: High

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Severity: Medium