CVE-2024-44246: Apple iPadOS

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.

Affected products

  • Apple iPadOS: before 17.7.3 (fixed in 17.7.3); from 18.0, before 18.2 (fixed in 18.2)
  • Apple iPhone OS: from 18.0, before 18.2 (fixed in 18.2)
  • Apple macOS: from 15.0, before 15.2 (fixed in 15.2)
  • Apple Safari: before 18.2 (fixed in 18.2)

Published 2024-12-12. Last modified 2026-06-17.