Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2024-40817
HistoryJul 29, 2024 - 10:16 p.m.

CVE-2024-40817

2024-07-2922:16:51
apple
github.com
6
ui handling
macos sonoma
safari 17.6
macos monterey
macos ventura
website security
ui spoofing

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

33.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

The issue was addressed with improved UI handling. This issue is fixed in macOS Sonoma 14.6, Safari 17.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.

CNA Affected

[
  {
    "vendor": "Apple",
    "product": "Safari",
    "versions": [
      {
        "status": "affected",
        "version": "unspecified",
        "lessThan": "17.6",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "status": "affected",
        "version": "unspecified",
        "lessThan": "13.6",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "status": "affected",
        "version": "unspecified",
        "lessThan": "14.6",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Apple",
    "product": "macOS",
    "versions": [
      {
        "status": "affected",
        "version": "unspecified",
        "lessThan": "12.7",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

5.8

Confidence

Low

EPSS

0.001

Percentile

33.0%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2024-40817