PT-2023-5289 · Apple+6 · Apple Macos+6

Joaxcar

+1

·

Published

2023-07-24

·

Updated

2025-01-28

·

CVE-2023-40397

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions macOS Ventura versions prior to 13.5 WebKitGTK (affected versions not specified) WPE WebKit (affected versions not specified)
Description The issue is related to errors in handling input data during code syntax analysis, which may allow a remote attacker to execute arbitrary javascript code. This can be achieved through the exploitation of vulnerabilities in the WebKitGTK and WPE WebKit modules, used for displaying web pages.
Recommendations For macOS Ventura, update to version 13.5 to resolve the issue. For WebKitGTK, restrict access to vulnerable modules to minimize the risk of exploitation until a patch is available. For WPE WebKit, consider disabling the execution of javascript code in the affected modules as a temporary workaround until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability in WebKitGTK and WPE WebKit.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

ALSA-2023:6535
ALSA-2023:7055
BDU:2023-05914
CESA-2023_7055
CVE-2023-40397
DSA-5468-1
MGASA-2024-0148
OPENSUSE-SU-2023_3753-1
RHSA-2023:6535
RHSA-2023:7055
RHSA-2023_6535
RHSA-2023_7055
RHSA-2024:8492
RHSA-2024:8496
RHSA-2024:9646
RHSA-2024:9653
RHSA-2024:9679
RHSA-2024:9680
RHSA-2025:10364
ROSA-SA-2025-2653
ROSA-SA-2025-2654
ROSA-SA-2025-2655
SUSE-SU-2023:3753-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Suse