CVE-2024-44187
6.5
MEDIUM
CVSS 3.1
EPSS 0.60%
Description
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. A malicious website may exfiltrate data cross-origin.
How to fix CVE-2024-44187
To remediate CVE-2024-44187, upgrade the affected package to a fixed version below.
- Debian/webkit2gtk—upgrade to 2.46.3-1~deb11u2 or later
- —no fix listed
Is CVE-2024-44187 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.46.3-1~deb11u2
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |