« List of all CVEs

CVE-2023-42843

Published: 2/21/2024 Last updated: 2/13/2025 Reserved: 9/14/2023

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

CNA assigner: apple (286789f9-fbc2-4510-9f9a-43facdede74c) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.5 High CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Opam packages affected (1)

javascriptcore

Products affected (4)

Product Vendor Version
iOS and iPadOS Apple 3.1.0 p3
Safari Apple < 6.1.7601.26816
macOS Apple < 10.0.17763.4010
iOS and iPadOS Apple < 19.3R2-S4, 19.3R3

References (12)