CVE-2023-41074
🟡 Monitoruj
Przetwarzanie treści internetowych w Apple może prowadzić do zdalnego wykonania kodu.
CVSS
8.8
EPSS
3.9%
Exploit
none
Vendor
apple
Opis źródłowy (NVD)
The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.9% |
| Opublikowano (NVD) | 2023-09-27 15:19:26 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 17:16:44 UTC |
Referencje
- http://seclists.org/fulldisclosure/2023/Oct/10 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2023/Oct/2 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2023/Oct/3 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2023/Oct/8 ([email protected]) [Mailing List, Third Party Advisory]
- http://seclists.org/fulldisclosure/2023/Oct/9 ([email protected]) [Mailing List, Third Party Advisory]
- http://www.openwall.com/lists/oss-security/2023/09/28/3 ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/[email protected]/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/ ([email protected]) [Mailing List, Third Party Advisory]
- https://security.gentoo.org/glsa/202401-33 ([email protected])
- https://support.apple.com/en-us/HT213936 ([email protected]) [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/HT213937 ([email protected]) [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/HT213938 ([email protected]) [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/HT213940 ([email protected]) [Release Notes, Vendor Advisory]
- https://support.apple.com/en-us/HT213941 ([email protected]) [Release Notes, Vendor Advisory]
- https://www.debian.org/security/2023/dsa-5527 ([email protected]) [Third Party Advisory]
- https://webkitgtk.org/security/WSA-2023-0009.html (af854a3a-2127-422b-91ae-364da2661108)