This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, visionOS 1.2. A maliciously crafted webpage may be able to fingerprint the user.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade webkitgtk4Upgrade webkitgtk4-jsc-develUpgrade webkitgtk4-develUpgrade webkitgtk4-jscUpgrade webkitgtk4-debuginfo | May 30, 2025 | Jun 10, 2024 |
| Apple Osx Webkit | — | Upgrade macOS to the latest version | Jun 11, 2024 | Jun 11, 2024 |
| Apple Safari | — | Upgrade to Apple Safari version 17.5Uninstall Apple Safari on Windows | Jun 11, 2024 | Jun 11, 2024 |
| Debian | — | Upgrade webkit2gtkUpgrade wpewebkit | Sep 27, 2024 | Jun 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub