发布时间: 2024年11月26日
修改时间: 2025年1月4日
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.
NVD | openEuler | |
---|---|---|
CVSS评分 | 6.1 | 6.3 |
Attack Vector | Network | Network |
Attack Complexity | Low | Low |
Privileges Required | None | None |
User Interaction | Required | Required |
Scope | Changed | Unchanged |
Confidentiality | Low | Low |
Integrity | Low | Low |
Availability | None | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2024-4174 | A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems. | 2024年11月26日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | webkit2gtk3 | Unaffected |
KY3.5.2 | webkit2gtk3 | Unaffected |
V6 | webkit2gtk3 | Unaffected |