The issue was addressed with improved input validation. This issue is fixed in Safari 18.4, visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A malicious website may be able to claim WebAuthn credentials from another website that shares a registrable suffix.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://support.apple.com/en-us/122371 | vendor advisory |
https://support.apple.com/en-us/122373 | vendor advisory |
https://support.apple.com/en-us/122378 | vendor advisory |
https://support.apple.com/en-us/122379 | vendor advisory |