CVE-2023-23496

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

11 Mar 2025, 14:15

Type Values Removed Values Added
CWE CWE-94

Information

Published : 2023-02-27 20:15

Updated : 2025-03-11 14:15


NVD link : CVE-2023-23496

Mitre link : CVE-2023-23496

CVE.ORG link : CVE-2023-23496


JSON object : View

Products Affected

apple

  • tvos
  • safari
  • watchos
  • ipados
  • iphone_os
  • macos
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')