CVE-2023-38572

The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. A website may be able to bypass Same Origin Policy.
References
Link Resource
http://www.openwall.com/lists/oss-security/2023/08/02/1 Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJ4DG5LHWG2INDOTPB7MO4JVJN6LKL3M/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/
https://security.gentoo.org/glsa/202401-04
https://support.apple.com/en-us/HT213841 Vendor Advisory
https://support.apple.com/en-us/HT213842 Vendor Advisory
https://support.apple.com/en-us/HT213843 Vendor Advisory
https://support.apple.com/en-us/HT213846 Vendor Advisory
https://support.apple.com/en-us/HT213847 Vendor Advisory
https://support.apple.com/en-us/HT213848 Vendor Advisory
https://www.debian.org/security/2023/dsa-5468
http://www.openwall.com/lists/oss-security/2023/08/02/1 Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJ4DG5LHWG2INDOTPB7MO4JVJN6LKL3M/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/
https://security.gentoo.org/glsa/202401-04
https://support.apple.com/en-us/HT213841 Vendor Advisory
https://support.apple.com/en-us/HT213842 Vendor Advisory
https://support.apple.com/en-us/HT213843 Vendor Advisory
https://support.apple.com/en-us/HT213846 Vendor Advisory
https://support.apple.com/en-us/HT213847 Vendor Advisory
https://support.apple.com/en-us/HT213848 Vendor Advisory
https://www.debian.org/security/2023/dsa-5468
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-07-27 01:15

Updated : 2024-11-21 08:13


NVD link : CVE-2023-38572

Mitre link : CVE-2023-38572

CVE.ORG link : CVE-2023-38572


JSON object : View

Products Affected

apple

  • tvos
  • safari
  • watchos
  • ipados
  • iphone_os
  • macos