The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NApple Music
APPApple< 1.5.0.152Microsoft Windows 10 22h2
OSMicrosoftall versionsMicrosoft Windows 11 24h2
OSMicrosoftall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
References
Related vulnerabilities
CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
CVE-2026-62815CRITICAL9.8same product
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
CVE-2026-49798CRITICAL9.3PL ✓same product
Use-after-free w Windows Kernel umożliwia lokalne privilege escalation
CVE-2026-42990CRITICAL9.8PL ✓same product
Heap buffer overflow w sterowniku ODBC SQL Server — zdalne wykonanie kodu
CVE-2026-49172CRITICAL9.8PL ✓same product
Heap-based buffer overflow w Windows FTP Service umożliwiający RCE