The issue was addressed with improved checks. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A website may be able to access sensor information without user consent.
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Safari | Apple | * | 18.4 (excluding) |
Ipados | Apple | * | 18.4 (excluding) |
Iphone_os | Apple | * | 18.4 (excluding) |
Macos | Apple | 15.0 (including) | 15.4 (excluding) |