Information disclosure in macOS - CVE-2024-44246
Published: December 11, 2024
Vulnerability identifier: #VU101709
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-44246
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in Safari on a device with Private Relay enabled. When adding a website to the Safari Reading List may reveal the originating IP address to the website.
Affected software
macOS
iPadOS
Apple iOS
Apple Safari
iPadOS
Apple iOS
Apple Safari
How to mitigate CVE-2024-44246
Install updates from vendor's website.
macOS - update to 15.2 24C101
Apple Safari - update to 18.2
iPadOS - addressed in versions 17.7.3, 18.2 22C152
Apple iOS - update to 18.2 22C152
Apple Safari - update to 18.2
iPadOS - addressed in versions 17.7.3, 18.2 22C152
Apple iOS - update to 18.2 22C152