CVE-2024-54467

A cookie management issue was addressed with improved state management. This issue is fixed in watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.
References
Link Resource
https://support.apple.com/en-us/121238 Release Notes Vendor Advisory
https://support.apple.com/en-us/121240 Release Notes Vendor Advisory
https://support.apple.com/en-us/121241 Release Notes Vendor Advisory
https://support.apple.com/en-us/121248 Release Notes Vendor Advisory
https://support.apple.com/en-us/121249 Release Notes Vendor Advisory
https://support.apple.com/en-us/121250 Release Notes Vendor Advisory
https://lists.debian.org/debian-lts-announce/2025/06/msg00016.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

03 Nov 2025, 20:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/06/msg00016.html -
References () https://support.apple.com/en-us/121238 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/121238 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121240 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/121240 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121241 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/121241 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121248 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/121248 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121249 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/121249 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/121250 - Vendor Advisory, Release Notes () https://support.apple.com/en-us/121250 - Release Notes, Vendor Advisory

14 Mar 2025, 11:59

Type Values Removed Values Added
References () https://support.apple.com/en-us/121238 - () https://support.apple.com/en-us/121238 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121240 - () https://support.apple.com/en-us/121240 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121241 - () https://support.apple.com/en-us/121241 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121248 - () https://support.apple.com/en-us/121248 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121249 - () https://support.apple.com/en-us/121249 - Vendor Advisory, Release Notes
References () https://support.apple.com/en-us/121250 - () https://support.apple.com/en-us/121250 - Vendor Advisory, Release Notes
First Time Apple safari
Apple tvos
Apple iphone Os
Apple ipados
Apple watchos
Apple
Apple macos
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Summary
  • (es) Se solucionó un problema de administración de cookies con una mejor administración del estado. Este problema se solucionó en watchOS 11, macOS Sequoia 15, Safari 18, visionOS 2, iOS 18, iPadOS 18 y tvOS 18. Un sitio web malicioso puede filtrar datos de origen cruzado.
CWE NVD-CWE-noinfo

11 Mar 2025, 03:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

10 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-10 19:15

Updated : 2025-11-03 20:16


NVD link : CVE-2024-54467

Mitre link : CVE-2024-54467

CVE.ORG link : CVE-2024-54467


JSON object : View

Products Affected

apple

  • tvos
  • ipados
  • safari
  • macos
  • watchos
  • iphone_os
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor