This issue was addressed through improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Processing maliciously crafted web content may lead to universal cross site scripting.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-webkitgtk4amazon-linux-ami-2-upgrade-webkitgtk4-debuginfoamazon-linux-ami-2-upgrade-webkitgtk4-develamazon-linux-ami-2-upgrade-webkitgtk4-jscamazon-linux-ami-2-upgrade-webkitgtk4-jsc-devel | May 30, 2025 | Sep 17, 2024 | |
| Apple Osx Webkit | apple-osx-upgrade-latest | Oct 31, 2024 | Sep 17, 2024 | |
| Apple Safari | apple-safari-upgrade-latest | Oct 14, 2024 | Sep 16, 2024 | |
| Debian | debian-upgrade-webkit2gtkdebian-upgrade-wpewebkit | Oct 16, 2024 | Sep 17, 2024 | |
| Gentoo Linux | gentoo-linux-upgrade-net-libs-webkit-gtk | Nov 25, 2025 | Nov 24, 2025 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Sep 17, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub