CVE-2024-54467

A cookie management issue was addressed with improved state management. This issue is fixed in watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.
References
Link Resource
https://support.apple.com/en-us/121238 Vendor Advisory Release Notes
https://support.apple.com/en-us/121240 Vendor Advisory Release Notes
https://support.apple.com/en-us/121241 Vendor Advisory Release Notes
https://support.apple.com/en-us/121248 Vendor Advisory Release Notes
https://support.apple.com/en-us/121249 Vendor Advisory Release Notes
https://support.apple.com/en-us/121250 Vendor Advisory Release Notes
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

14 Mar 2025, 11:59

Type Values Removed Values Added
References () https://support.apple.com/en-us/121238 - () https://support.apple.com/en-us/121238 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121240 - () https://support.apple.com/en-us/121240 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121241 - () https://support.apple.com/en-us/121241 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121248 - () https://support.apple.com/en-us/121248 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121249 - () https://support.apple.com/en-us/121249 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121250 - () https://support.apple.com/en-us/121250 - Vendor Advisory, Release Notes
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
First Time Apple macos
Apple
Apple watchos
Apple safari
Apple ipados
Apple tvos
Apple iphone Os
Summary
  • (es) Se solucionó un problema de administración de cookies con una mejor administración del estado. Este problema se solucionó en watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18, iPadOS 18 y tvOS 18. Un sitio web malicioso puede filtrar datos de origen cruzado.

11 Mar 2025, 03:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

10 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 19:15

Updated : 2025-03-14 11:59


NVD link : CVE-2024-54467

Mitre link : CVE-2024-54467

CVE.ORG link : CVE-2024-54467


JSON object : View

Products Affected

apple

  • watchos
  • iphone_os
  • ipados
  • safari
  • macos
  • tvos
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor