{"id":"CVE-2024-23280","details":"An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.","modified":"2026-03-15T22:49:19.407314Z","published":"2024-03-08T02:15:49.740Z","related":["MGASA-2024-0148","SUSE-SU-2024:1269-1","SUSE-SU-2024:1270-1","SUSE-SU-2024:1293-1","SUSE-SU-2024:1944-1","SUSE-SU-2024:1976-1"],"references":[{"type":"WEB","url":"https://support.apple.com/kb/HT214089"},{"type":"WEB","url":"https://support.apple.com/kb/HT214086"},{"type":"WEB","url":"https://support.apple.com/kb/HT214081"},{"type":"WEB","url":"https://support.apple.com/kb/HT214084"},{"type":"ADVISORY","url":"https://support.apple.com/en-us/HT214086"},{"type":"ADVISORY","url":"https://support.apple.com/en-us/HT214089"},{"type":"ADVISORY","url":"https://support.apple.com/en-us/HT214081"},{"type":"ADVISORY","url":"https://support.apple.com/en-us/HT214084"},{"type":"ADVISORY","url":"https://support.apple.com/en-us/HT214088"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2024/Mar/21"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2024/Mar/24"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2024/Mar/25"},{"type":"ARTICLE","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/"},{"type":"ARTICLE","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF/"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/03/26/1"},{"type":"ARTICLE","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AO4BNNL5X2LQBJ6WX7VT4SGMA6R7DUU5/"},{"type":"ARTICLE","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI/"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2024/Mar/20"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"17.4"}]},{"events":[{"introduced":"0"},{"fixed":"17.4"}]},{"events":[{"introduced":"0"},{"fixed":"17.4"}]},{"events":[{"introduced":"14.0"},{"fixed":"14.4"}]},{"events":[{"introduced":"0"},{"fixed":"17.4"}]},{"events":[{"introduced":"0"},{"fixed":"10.4"}]},{"events":[{"introduced":"0"},{"last_affected":"38"}]},{"events":[{"introduced":"0"},{"last_affected":"39"}]},{"events":[{"introduced":"0"},{"last_affected":"40"}]},{"events":[{"introduced":"0"},{"fixed":"2.44.0"}]},{"events":[{"introduced":"0"},{"fixed":"2.44.0"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-23280.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}