T
his issue was addressed through improved state management. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, Safari 18.1. An attacker may be able to misuse a trust relationship to download malicious content.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/121563 | Vendor Advisory |
| https://support.apple.com/en-us/121564 | Vendor Advisory |
| https://support.apple.com/en-us/121566 | Vendor Advisory |
| https://support.apple.com/en-us/121567 | Vendor Advisory |
| https://support.apple.com/en-us/121571 | Vendor Advisory |
| http://seclists.org/fulldisclosure/2024/Oct/10 | |
| http://seclists.org/fulldisclosure/2024/Oct/11 | |
| http://seclists.org/fulldisclosure/2024/Oct/19 | |
| http://seclists.org/fulldisclosure/2024/Oct/9 |
Configurations
Configuration 1 (hide)
|
History
03 Nov 2025, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 Dec 2024, 18:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.apple.com/en-us/121563 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/121564 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/121566 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/121567 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/121571 - Vendor Advisory | |
| CPE | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | NVD-CWE-noinfo | |
| First Time |
Apple macos
Apple safari Apple iphone Os Apple ipados Apple visionos Apple |
29 Oct 2024, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) This issue was addressed through improved state management. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, Safari 18.1. An attacker may be able to misuse a trust relationship to download malicious content. |
29 Oct 2024, 20:35
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
29 Oct 2024, 14:34
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
28 Oct 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-10-28 21:15
Updated : 2025-11-03 23:15
NVD link : CVE-2024-44259
Mitre link : CVE-2024-44259
CVE.ORG link : CVE-2024-44259
JSON object : View
CWE