
Cloud Vulnerability DB
A community-led vulnerabilities database
An authentication issue was discovered in Safari Private Browsing that affects Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. The vulnerability (CVE-2024-54542) was reported by Rei (@reizydev) and Kenneth Chew, and was officially disclosed on January 27, 2025. The issue allows Private Browsing tabs to be accessed without proper authentication (Apple Support, CVE).
The vulnerability stems from an authentication issue in Safari's Private Browsing feature. The security flaw was addressed by implementing improved state management in the affected systems. This indicates the vulnerability likely arose from improper handling of authentication states in the Private Browsing functionality (Apple Support).
The vulnerability allows unauthorized access to Private Browsing tabs, potentially exposing private browsing data and compromising user privacy. This breach of Private Browsing security could reveal sensitive information that users specifically intended to keep private (Apple Support).
Apple has addressed the vulnerability by implementing improved state management in the affected systems. Users are advised to update to Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2, or iPadOS 18.2, depending on their device (Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."