First published: Fri Sep 29 2023(Updated: )
An attacker with JavaScript execution may be able to execute arbitrary code. This issue was addressed with improved iframe sandbox enforcement. Reference: <a href="https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-40451">https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-40451</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Apple WebKit |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2241409 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
To fix REDHAT-BUG-2241409, ensure that you update your Apple WebKit to the latest version where the iframe sandbox enforcement has been improved.
The vulnerability REDHAT-BUG-2241409 is caused by inadequate sandboxing of iframes, allowing an attacker with JavaScript execution to run arbitrary code.
Users of Apple WebKit are affected by REDHAT-BUG-2241409 if they are using an outdated version of the software.
REDHAT-BUG-2241409 was disclosed in the 2023 security advisory for Apple WebKit.