PT-2023-8192 · Apple+7 · Apple Macos+13

Francisco Alonso

+1

·

Published

2023-09-26

·

Updated

2024-08-20

·

CVE-2023-40414

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions watchOS versions prior to 10 iOS versions prior to 17 iPadOS versions prior to 17 tvOS versions prior to 17 macOS versions prior to Sonoma 14 Safari versions prior to 17
Description The issue is related to a use-after-free problem in the WebKit component, which can be exploited by a remote attacker to execute arbitrary code using a specially crafted link. Processing web content may lead to arbitrary code execution. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For watchOS versions prior to 10, update to watchOS 10 or later. For iOS versions prior to 17, update to iOS 17 or later. For iPadOS versions prior to 17, update to iPadOS 17 or later. For tvOS versions prior to 17, update to tvOS 17 or later. For macOS versions prior to Sonoma 14, update to macOS Sonoma 14 or later. For Safari versions prior to 17, update to Safari 17 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ALSA-2024:2126
ALSA-2024:2982
BDU:2024-00184
CESA-2024_2982
CVE-2023-40414
DSA-5527-1
DSA-5527-2
INFSA-2024_2126
INFSA-2024_2982
MGASA-2024-0148
OPENSUSE-SU-2024_0548-1
RHSA-2024:2126
RHSA-2024:2982
RHSA-2024_2126
RHSA-2024_2982
RHSA-2025:10364
RLSA-2024:2982
SUSE-SU-2024:0519-1
SUSE-SU-2024:0545-1
SUSE-SU-2024:0548-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Rocky Linux
Safari
Suse
Webkit
Ios
Ipados
Tvos
Watchos