First published: Mon Jan 22 2024(Updated: )
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, Safari 17.3, tvOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
Credit: product-security@apple.com Noah Roskin-Frazee Pr Ian de Marcellus Mark Bowers Jubaer Alnazi @h33tjubaer Kirin @Pwnrin Zhongquan Li @Guluisacat an anonymous researcher Wangtaiyu Zhongfu infoJames Lee @Windowsrcer fmyy @binary_fmyy TIANGONG Team of Legendsec at QIlime TIANGONG Team of Legendsec at QIKoh M. Nakagawa FFRI Security IncClemens Lang Ye Zhang Baidu Security
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <14.3 | 14.3 |
tvOS | <17.3 | 17.3 |
Apple Mobile Safari | <17.3 | 17.3 |
Apple Mobile Safari | <17.3 | |
Apple iOS, iPadOS, and watchOS | <17.3 | |
iOS | <17.3 | |
Apple iOS and macOS | >=14.0<14.3 | |
tvOS | <17.3 | |
Apple iOS, iPadOS, and watchOS | <10.3 | |
Apple iOS, iPadOS, and watchOS | <10.3 | 10.3 |
Apple iOS, iPadOS, and watchOS | <17.3 | 17.3 |
Apple iOS, iPadOS, and watchOS | <17.3 | 17.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2024-23271 is a high-severity vulnerability due to its potential for causing unexpected cross-origin behavior.
To fix CVE-2024-23271, update your device to the latest software version, specifically iOS 17.3, iPadOS 17.3, Safari 17.3, tvOS 17.3, watchOS 10.3, or macOS Sonoma 14.3.
CVE-2024-23271 affects Apple devices running iOS, iPadOS, Safari, tvOS, watchOS, and macOS prior to the specified updated versions.
CVE-2024-23271 is classified as a logic issue that can lead to cross-origin problems on affected systems.
If exploited, CVE-2024-23271 may allow attackers to perform unauthorized actions on behalf of users, leading to privacy and security breaches.