This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-27856.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-27856.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-40789.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.3. The following CVEs are assigned: CVE-2024-40789.
Workspace ONE Launcher contains a Privilege Escalation Vulnerability. A malicious actor with physical access to Workspace ONE Launcher could utilize the Edge Panel feature to bypass setup to gain access to sensitive information.
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
Microsoft Power Platform Connector Spoofing Vulnerability
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability
An attacker with JavaScript execution may be able to execute arbitrary code. This issue was addressed with improved iframe sandbox enforcement.
Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-40451
Versions affected: WebKitGTK and WPE WebKit before 2.40.5. Credit to Johan Carlsson (joaxcar). Impact: A remote attacker may be able to cause arbitrary javascript code execution. Description: The issue was addressed with improved checks.
Versions affected: WebKitGTK and WPE WebKit before 2.40.1. Credit to Gertjan Franken of imec-DistriNet, KU Leuven. Impact: Content Security Policy to block domains with wildcards may fail. Description: A logic issue was addressed with improved validation.
Versions affected: WebKitGTK and WPE WebKit before 2.40.1. Credit to hazbinhotel working with Trend Micro Zero Day Initiative. Impact: Processing web content may lead to arbitrary code execution. Description: A use-after-free issue was addressed with improved memory management.
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. A memory corruption issue was addressed with improved state management.
Reference: https://webkitgtk.org/security/WSA-2023-0005.html
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Apple WebKit. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
CVE-2023-28205 (WebKit)
It is a use-after-free vulnerability that allows attackers to process maliciously crafted web content that may lead to arbitrary code execution.
By tricking targets into loading malicious websites under the control of attackers, it is possible to exploit the vulnerability, which could lead to the execution of malware on compromised systems. Maliciously designed web content can cause the execution of arbitrary code, giving attackers access to your device without your knowledge. Apple has fixed this vulnerability with improved memory management.
WebKit Bugzilla: 254797
https://seclists.org/fulldisclosure/2023/Apr/1 https://seclists.org/fulldisclosure/2023/Apr/2 https://seclists.org/fulldisclosure/2023/Apr/3
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
WebKit. Multiple memory corruption issues were addressed with improved memory handling.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.