• CVE-2024-40776

发布时间: 2024年8月21日

修改时间: 2024年8月21日

概要

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

CVSS v3 指标

NVD openEuler
CVSS评分 4.3 8.1
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction Required Required
Scope Unchanged Unchanged
Confidentiality None None
Integrity None High
Availability Low High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3395 A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash. 2024年8月21日

影响产品

产品 状态
KY3.4-5A webkit2gtk3 Unaffected
KY3.5.2 webkit2gtk3 Unaffected
V6 webkit2gtk3 Unaffected