First published: Mon Mar 27 2023(Updated: )
A logic issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. Content Security Policy to block domains with wildcards may fail.
Credit: product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | >=13.0<13.3 | |
WebKitGTK WebKitGTK | <2.40.1 | |
Wpewebkit Wpe Webkit | <2.40.1 | |
Apple Safari | <16.4 | 16.4 |
<16.4 | 16.4 | |
<16.4 | 16.4 | |
Apple macOS Ventura | <13.3 | 13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-32370.
The severity of CVE-2023-32370 is medium, with a severity value of 5.3.
The affected software for CVE-2023-32370 is macOS Ventura 13.3 and Apple macOS versions 13.0 to 13.3.
To fix this vulnerability, update to macOS Ventura 13.3 or later.
Yes, you can find references for CVE-2023-32370 at the following links: [1] https://support.apple.com/en-us/HT213670 [2] http://www.openwall.com/lists/oss-security/2023/09/11/1