CVE-2024-23254
Apple Safari ≤ 17.4
CVSS Score v3.1
6.5
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.013
67th percentile
Summary
CVE-2024-23254 is a medium-severity an unspecified weakness vulnerability in Apple Safari. Its CVSS base score is 6.5 (Medium).
Operationally, ranked in the top 33% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-20773
Vulnerability Data
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2024-23280Same product: Apple Ipad Os
CVE-2024-23263Same product: Apple Iphone Os
CVE-2024-23284Same product: Apple Iphone Os
CVE-2024-27834Same product: Apple Iphone Os
CVE-2023-42843Same product: Apple Ipad Os
CVE-2025-43342Same product: Apple Iphone Os
CVE-2025-43343Same product: Apple Iphone Os
CVE-2021-30952Same product: Apple Iphone Os
CVE-2022-32893Same product: Apple Iphone Os
CVE-2021-1789Same product: Apple Iphone Os
Affected Assets
apple
safari
≤ 17.4
apple
ipad os
≤ 17.4
apple
iphone os
≤ 17.4
apple
macos
≤ 14.4
apple
tvos
≤ 17.4
apple
visionos
≤ 1.1
apple
watchos
≤ 10.4
fedoraproject
fedora
40
webkitgtk
webkitgtk
≤ 2.44.0
wpewebkit
wpe webkit
≤ 2.44.0
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.