Medium CVSS 6.5 webkit Cross Origin

Overview

Medium
Severity
6.5
CVSS
No
Exploited ITW
Embargoed
Fix Status
DescriptionA malicious website may exfiltrate data cross-origin
ComponentWebKit
Bug ClassCross Origin
Tracker279452
CWECWE-346 (Origin validation error)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA KEVNot listed
CreditedNarendra Bhati, Manager of Cyber Security at Suma Soft Pvt. Ltd, Pune (India)
Disclosed2024-09-16

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.

Original Bug Report

The reporter's bug is still restricted on the tracker.