yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2024-23254
Component Overview
Vulnerability Overview
Name
CVE-2024-23254
Source
NVD (
link
)
Debian (
link
)
Description
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
CWEs
Published Date
Mar 8, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://seclists.org/fulldisclosure/2024/Mar/20
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/21
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/24
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/25
Mailing List
http://seclists.org/fulldisclosure/2024/Mar/26
Mailing List
http://www.openwall.com/lists/oss-security/2024/03/26/1
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/
Mailing List
https://support.apple.com/en-us/HT214081
Vendor Advisory
https://support.apple.com/en-us/HT214084
Vendor Advisory
https://support.apple.com/en-us/HT214086
Vendor Advisory
https://support.apple.com/en-us/HT214087
Vendor Advisory
https://support.apple.com/en-us/HT214088
Vendor Advisory
https://support.apple.com/en-us/HT214089
Vendor Advisory
Analysis
#
Affected Component
Analysis
webkitgtk
Exploitable
Vulnerability Ratings
#
6.5
CVSSv31
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
webkitgtk
buildroot
2025.02.x
2.52.3
Not Affected
webkitgtk
buildroot
master
2.52.3
Not Affected
webkitgtk
yocto
master
2.50.6
Not Affected
webkitgtk
yocto
scarthgap
2.44.4
Not Affected