PT-2023-5289 · Apple+6 · Apple Macos+6
Joaxcar
+1
·
Published
2023-07-24
·
Updated
2025-01-28
·
CVE-2023-40397
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
macOS Ventura versions prior to 13.5
WebKitGTK (affected versions not specified)
WPE WebKit (affected versions not specified)
Description
The issue is related to errors in handling input data during code syntax analysis, which may allow a remote attacker to execute arbitrary javascript code. This can be achieved through the exploitation of vulnerabilities in the WebKitGTK and WPE WebKit modules, used for displaying web pages.
Recommendations
For macOS Ventura, update to version 13.5 to resolve the issue.
For WebKitGTK, restrict access to vulnerable modules to minimize the risk of exploitation until a patch is available.
For WPE WebKit, consider disabling the execution of javascript code in the affected modules as a temporary workaround until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability in WebKitGTK and WPE WebKit.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Suse