First published: Mon Jul 24 2023(Updated: )
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.
Credit: product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <16.6 | 16.6 |
Apple iPadOS | <16.6 | 16.6 |
<13.5 | 13.5 | |
Apple macOS | <13.5 | |
WebKitGTK WebKitGTK | <2.40.5 | |
Wpewebkit Wpe Webkit | <2.40.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID is CVE-2023-40397.
The severity of CVE-2023-40397 is critical, with a severity value of 9.8.
CVE-2023-40397 was addressed with improved checks in macOS Ventura 13.5.
The affected software for CVE-2023-40397 is Apple macOS Ventura up to version 13.5.
Yes, you can find a reference link for CVE-2023-40397 [here](https://support.apple.com/en-us/HT213843) and [here](http://www.openwall.com/lists/oss-security/2023/09/11/1).