CVE-2023-40448 Information
Sep 30, 2023
cve
Description
The issue was addressed with improved handling of protocols. This issue is fixed in tvOS 17 iOS 16.7 and iPadOS 16.7 watchOS 10 iOS 17 and iPadOS 17 macOS Sonoma 14. A remote attacker may be able to break out of Web Content sandbox.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Reference
https://support.apple.com/en-us/HT213937 https://support.apple.com/en-us/HT213938 https://support.apple.com/en-us/HT213927 https://support.apple.com/en-us/HT213936 https://support.apple.com/en-us/HT213940
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.6
Share on: