First published: Wed Oct 25 2023(Updated: )
Core Recents. The issue was resolved by sanitizing logging
Credit: Alex Renda product-security@apple.com Adam M. JZ an anonymous researcher Linus Henze Pinauten GmbHinooo Mickey Jin @patch1t Grzegorz Riegel Talal Haj Bakry Mysk IncTommy Mysk @mysk_co Mysk IncMingxuan Yang @PPPF00L 360 Vulnerability Research Institutehappybabywu 360 Vulnerability Research InstituteGuang Gong 360 Vulnerability Research Institute 360 Vulnerability Research InstituteBistrit Dahal Cristian Dinca Computer ScienceRomania Claire Houston 이준성(Junsung Lee) Cross RepublicPedro Ribeiro @pedrib1337 Agile Information SecurityVitor Pedreira @0xvhp_ Agile Information Security이준성(Junsung Lee) Kacper Kwapisz @KKKas_ Tomi Tokics @tomitokics iTomsn0wCVE-2023-42823
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.1 | 14.1 |
Apple iOS and iPadOS | <16.7.2 | 16.7.2 |
Apple iOS, iPadOS, and macOS | <16.7.2 | 16.7.2 |
Apple iOS, iPadOS, and macOS | <16.7.2 | |
iPhone OS | <16.7.2 | |
macOS | >=14.0<14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-41977 is a vulnerability in Safari that allows a malicious website to reveal browsing history.
CVE-2023-41977 is fixed in macOS Sonoma 14.1, iOS 16.7.2, and iPadOS 16.7.2.
Yes, there are security updates available for CVE-2023-41977. You can find more information at the Apple support website.
Yes, visiting a malicious website can trigger CVE-2023-41977 and reveal browsing history.
You can find more information about CVE-2023-41977 at the Apple support website.