CVE-2023-40448 is a high-severity vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS operating systems, allowing a remote attacker to escape the Web Content sandbox due to inadequate protocol handling. With a CVSS score of 8.6, this vulnerability poses a significant risk as it can be exploited remotely without user interaction, leading to high integrity impacts. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability has been addressed in recent updates including iOS 17, iPadOS 17, macOS Sonoma 14, tvOS 17, and watchOS 10.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.7CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 16.7CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 14.0CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 17.0CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 10.0CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.