PT-2023-8192 · Apple+7 · Apple Macos+13
Francisco Alonso
+1
·
Published
2023-09-26
·
Updated
2024-08-20
·
CVE-2023-40414
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
watchOS versions prior to 10
iOS versions prior to 17
iPadOS versions prior to 17
tvOS versions prior to 17
macOS versions prior to Sonoma 14
Safari versions prior to 17
Description
The issue is related to a use-after-free problem in the WebKit component, which can be exploited by a remote attacker to execute arbitrary code using a specially crafted link. Processing web content may lead to arbitrary code execution. The estimated number of potentially affected devices worldwide is not specified.
Recommendations
For watchOS versions prior to 10, update to watchOS 10 or later.
For iOS versions prior to 17, update to iOS 17 or later.
For iPadOS versions prior to 17, update to iPadOS 17 or later.
For tvOS versions prior to 17, update to tvOS 17 or later.
For macOS versions prior to Sonoma 14, update to macOS Sonoma 14 or later.
For Safari versions prior to 17, update to Safari 17 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Apple Macos
Red Hat
Rocky Linux
Safari
Suse
Webkit
Ios
Ipados
Tvos
Watchos