Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-40448

24
FAUCET Score

CVE-2023-40448 is a high-severity vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS operating systems, allowing a remote attacker to escape the Web Content sandbox due to inadequate protocol handling. With a CVSS score of 8.6, this vulnerability poses a significant risk as it can be exploited remotely without user interaction, leading to high integrity impacts. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability has been addressed in recent updates including iOS 17, iPadOS 17, macOS Sonoma 14, tvOS 17, and watchOS 10.

Impacted Technologies

VendorProductVersion(s)CPE
< 16.7CPE matchmatch criteria
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
< 16.7CPE matchmatch criteria
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
< 14.0CPE matchmatch criteria
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
< 17.0CPE matchmatch criteria
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
< 10.0CPE matchmatch criteria
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.57%
Probability of exploitation in next 30 days
EPSS Percentile
72.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0157 is in the 55th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

applevendor investigatingvia nvd_reference
View patch

References

support.apple.com / kb/HT213927
support.apple.com / kb/HT213936
support.apple.com / kb/HT213937
support.apple.com / kb/HT213938
support.apple.com / kb/HT213940
seclists.org / fulldisclosure/2023/Oct/10
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2023/Oct/3
seclists.org / fulldisclosure/2023/Oct/4
seclists.org / fulldisclosure/2023/Oct/8
support.apple.com / en-us/HT213927
Vendor Advisory
support.apple.com / en-us/HT213936
Vendor Advisory
support.apple.com / en-us/HT213937
Vendor Advisory
support.apple.com / en-us/HT213938
Vendor Advisory
support.apple.com / en-us/HT213940
Vendor Advisory