Cyber Resilience

CVE-2024-23254

Apple Safari ≤ 17.4

Published
08 March 2024
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score 0.013 67th percentile
Risk Priority 53 floored blend · peak EPSS

Summary

CVE-2024-23254 is a medium-severity an unspecified weakness vulnerability in Apple Safari. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 33% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-23280Same product: Apple Ipad Os
CVE-2024-23263Same product: Apple Iphone Os
CVE-2024-23284Same product: Apple Iphone Os
CVE-2024-27834Same product: Apple Iphone Os
CVE-2023-42843Same product: Apple Ipad Os
CVE-2025-43342Same product: Apple Iphone Os
CVE-2025-43343Same product: Apple Iphone Os
CVE-2021-30952Same product: Apple Iphone Os
CVE-2022-32893Same product: Apple Iphone Os
CVE-2021-1789Same product: Apple Iphone Os

Affected Assets

apple
safari
≤ 17.4
apple
ipad os
≤ 17.4
apple
iphone os
≤ 17.4
apple
macos
≤ 14.4
apple
tvos
≤ 17.4
apple
visionos
≤ 1.1
apple
watchos
≤ 10.4
fedoraproject
fedora
40
webkitgtk
webkitgtk
≤ 2.44.0
wpewebkit
wpe webkit
≤ 2.44.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References