This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/120909 | |
| https://support.apple.com/en-us/120911 | |
| https://support.apple.com/en-us/120913 | |
| http://seclists.org/fulldisclosure/2024/Jul/15 | Mailing List Third Party Advisory |
| http://seclists.org/fulldisclosure/2024/Jul/16 | Mailing List Third Party Advisory |
| http://seclists.org/fulldisclosure/2024/Jul/18 | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/09/msg00006.html | |
| https://support.apple.com/en-us/HT214117 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/HT214119 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/HT214121 | Release Notes Vendor Advisory |
| https://support.apple.com/kb/HT214117 | |
| https://support.apple.com/kb/HT214119 | |
| https://support.apple.com/kb/HT214121 |
Configurations
Configuration 1 (hide)
|
History
02 Apr 2026, 19:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | (en) This issue was addressed through improved state management. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Private Browsing tabs may be accessed without authentication. |
04 Nov 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Nov 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
14 Mar 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 |
21 Nov 2024, 09:31
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://seclists.org/fulldisclosure/2024/Jul/15 - Mailing List, Third Party Advisory | |
| References | () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory | |
| References | () http://seclists.org/fulldisclosure/2024/Jul/18 - Mailing List, Third Party Advisory | |
| References | () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT214119 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT214121 - Release Notes, Vendor Advisory |
23 Aug 2024, 15:18
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo | |
| First Time |
Apple
Apple safari Apple ipados Apple iphone Os Apple macos |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| References | () http://seclists.org/fulldisclosure/2024/Jul/15 - Mailing List, Third Party Advisory | |
| References | () http://seclists.org/fulldisclosure/2024/Jul/16 - Mailing List, Third Party Advisory | |
| References | () http://seclists.org/fulldisclosure/2024/Jul/18 - Mailing List, Third Party Advisory | |
| References | () https://support.apple.com/en-us/HT214117 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT214119 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT214121 - Release Notes, Vendor Advisory |
30 Jul 2024, 13:32
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
30 Jul 2024, 02:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jul 2024, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
29 Jul 2024, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-07-29 23:15
Updated : 2026-04-02 19:17
NVD link : CVE-2024-40794
Mitre link : CVE-2024-40794
CVE.ORG link : CVE-2024-40794
JSON object : View
Products Affected
apple
- ipados
- safari
- macos
- iphone_os
CWE
