The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://support.apple.com/en-us/121839 | vendor advisory |
https://support.apple.com/en-us/121838 | vendor advisory |
https://support.apple.com/en-us/121837 | vendor advisory |
https://support.apple.com/en-us/121846 | vendor advisory |