PT-2023-6792 · Apple+6 · Apple Macos+6

Gertjan Franken

·

Published

2023-03-27

·

Updated

2025-01-28

·

CVE-2023-32370

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions macOS versions prior to 13.3 WebKitGTK (affected versions not specified) WPE WebKit (affected versions not specified)
Description The issue is related to insufficient input validation, which may allow a remote attacker to impact data integrity. A logic issue was addressed with improved validation. The Content Security Policy to block domains with wildcards may fail.
Recommendations For macOS versions prior to 13.3, update to macOS Ventura 13.3 to resolve the issue. For WebKitGTK, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For WPE WebKit, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:6535
ALSA-2023:7055
BDU:2023-07654
CESA-2023_7055
CVE-2023-32370
DSA-5396-1
DSA-5396-2
OPENSUSE-SU-2023_3753-1
RHSA-2023:6535
RHSA-2023:7055
RHSA-2023_6535
RHSA-2023_7055
RHSA-2025:10364
ROSA-SA-2025-2653
ROSA-SA-2025-2654
ROSA-SA-2025-2655
SUSE-SU-2023:3753-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Suse