Safari Apple Safari

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apple Safari.

Recent Apple Safari Security Advisories

Advisory Title Published
122074 Safari 18.3 - Apple Security Content January 27, 2025
121846 Safari 18.2 - Apple Security Content December 11, 2024
121756 Safari 18.1.1 - Apple Security Content November 19, 2024
121571 Safari 18.1 - Apple Security Content October 29, 2024
121241 Safari 18 - Apple Security Content September 16, 2024
HT214121 Safari 17.6 Security Content July 29, 2024
HT214103 Safari 17.5 Security Content May 13, 2024
HT214094 Safari 17.4.1 Security Content March 25, 2024
HT214089 Safari 17.4 Security Content March 7, 2024
HT214056 Safari 17.3 Security Content January 22, 2024

Known Exploited Apple Safari Vulnerabilities

The following Apple Safari vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Apple Safari Webkit Browser Engine Buffer Overflow Vulnerability Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
CVE-2021-30665 Exploit Probability: 0.5%
November 3, 2021
Apple Safari Webkit Browser Engine Integer Overflow Vulnerability Integer overflow. Processing maliciously crafted web content may lead to arbitrary code execution.
CVE-2021-30663 Exploit Probability: 0.5%
November 3, 2021

By the Year

In 2025 there have been 8 vulnerabilities in Apple Safari with an average score of 6.7 out of ten. Last year, in 2024 Safari had 57 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Safari in 2025 could surpass last years number. Last year, the average CVE base score was greater by 0.09




Year Vulnerabilities Average Score
2025 8 6.70
2024 57 6.79
2023 44 7.87
2022 41 7.81
2021 35 7.66
2020 59 7.23
2019 166 8.13
2018 41 8.11

It may take a day or so for new Safari vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apple Safari Security Vulnerabilities

The issue was addressed with improved memory handling

CVE-2024-54543 8.8 - High - January 27, 2025

The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.2, tvOS 18.2, Safari 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. Processing maliciously crafted web content may lead to memory corruption.

Memory Corruption

A privacy issue was addressed with improved handling of files

CVE-2025-24150 8.8 - High - January 27, 2025

A privacy issue was addressed with improved handling of files. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Copying a URL from Web Inspector may lead to command injection.

Command Injection

This issue was addressed through improved state management

CVE-2025-24162 - January 27, 2025

This issue was addressed through improved state management. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to an unexpected process crash.

The issue was addressed with improved memory handling

CVE-2025-24158 - January 27, 2025

The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing web content may lead to a denial-of-service.

The issue was addressed with improved access restrictions to the file system

CVE-2025-24143 6.5 - Medium - January 27, 2025

The issue was addressed with improved access restrictions to the file system. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. A maliciously crafted webpage may be able to fingerprint the user.

The issue was addressed by adding additional logic

CVE-2025-24128 4.3 - Medium - January 27, 2025

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3. Visiting a malicious website may lead to address bar spoofing.

The issue was addressed with improved UI

CVE-2025-24113 4.3 - Medium - January 27, 2025

The issue was addressed with improved UI. This issue is fixed in macOS Sequoia 15.3, Safari 18.3, iOS 18.3 and iPadOS 18.3, visionOS 2.3. Visiting a malicious website may lead to user interface spoofing.

A logging issue was addressed with improved data redaction

CVE-2025-24169 7.5 - High - January 27, 2025

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.3, Safari 18.3. A malicious app may be able to bypass browser extension authentication.

A cookie management issue was addressed with improved state management

CVE-2024-44212 5.3 - Medium - December 12, 2024

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, visionOS 2.1, tvOS 18.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.

Origin Validation Error

The issue was addressed with improved memory handling

CVE-2024-54534 9.8 - Critical - December 12, 2024

The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.

Memory Corruption

A type confusion issue was addressed with improved memory handling

CVE-2024-54505 8.8 - High - December 12, 2024

A type confusion issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to memory corruption.

Object Type Confusion

The issue was addressed with improved memory handling

CVE-2024-54508 7.5 - High - December 12, 2024

The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.

The issue was addressed with improved checks

CVE-2024-54502 6.5 - Medium - December 12, 2024

The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.

The issue was addressed with improved checks

CVE-2024-54479 7.5 - High - December 12, 2024

The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.

The issue was addressed with improved routing of Safari-originated requests

CVE-2024-44246 5.3 - Medium - December 12, 2024

The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading List may reveal the originating IP address to the website.

Apple Safari and macOS Cookie Management Vulnerability Leading to XSS

CVE-2024-44309 6.1 - Medium - November 20, 2024

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site scripting attack. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

XSS

Apple Safari Web Content Arbitrary Code Execution

CVE-2024-44308 8.8 - High - November 20, 2024

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited on Intel-based Mac systems.

The issue was addressed with improved checks

CVE-2024-44296 5.4 - Medium - October 28, 2024

The issue was addressed with improved checks. This issue is fixed in tvOS 18.1, iOS 18.1 and iPadOS 18.1, iOS 17.7.1 and iPadOS 17.7.1, watchOS 11.1, visionOS 2.1, macOS Sequoia 15.1, Safari 18.1. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

An information leakage was addressed with additional validation

CVE-2024-44229 5.3 - Medium - October 28, 2024

An information leakage was addressed with additional validation. This issue is fixed in visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, Safari 18.1. Private browsing may leak some browsing history.

This issue was addressed through improved state management

CVE-2024-44259 7.5 - High - October 28, 2024

This issue was addressed through improved state management. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, visionOS 2.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, Safari 18.1. An attacker may be able to misuse a trust relationship to download malicious content.

A memory corruption issue was addressed with improved input validation

CVE-2024-44244 4.3 - Medium - October 28, 2024

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1, visionOS 2.1, tvOS 18.1, macOS Sequoia 15.1, Safari 18.1. Processing maliciously crafted web content may lead to an unexpected process crash.

Memory Corruption

A custom URL scheme handling issue was addressed with improved input validation

CVE-2024-44155 6.5 - Medium - October 28, 2024

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in Safari 18, iOS 17.7.1 and iPadOS 17.7.1, macOS Sequoia 15, watchOS 11, iOS 18 and iPadOS 18. Maliciously crafted web content may violate iframe sandboxing policy.

The issue was addressed with improved checks

CVE-2024-44185 5.5 - Medium - October 24, 2024

The issue was addressed with improved checks. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

Safari 17 web content restriction bypass

CVE-2024-44206 9.3 - Critical - October 24, 2024

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in tvOS 17.6, visionOS 1.3, Safari 17.6, watchOS 10.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. A user may be able to bypass some web content restrictions.

An authentication issue was addressed with improved state management

CVE-2024-44202 5.3 - Medium - September 17, 2024

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18 and iPadOS 18. Private Browsing tabs may be accessed without authentication.

authentification

This issue was addressed through improved state management

CVE-2024-40857 6.1 - Medium - September 17, 2024

This issue was addressed through improved state management. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. Processing maliciously crafted web content may lead to universal cross site scripting.

XSS

The issue was addressed with improved UI

CVE-2024-40866 6.5 - Medium - September 17, 2024

The issue was addressed with improved UI. This issue is fixed in Safari 18, macOS Sequoia 15. Visiting a malicious website may lead to address bar spoofing.

A cross-origin issue existed with "iframe" elements

CVE-2024-44187 6.5 - Medium - September 17, 2024

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. A malicious website may exfiltrate data cross-origin.

Origin Validation Error

A use-after-free issue was addressed with improved memory management

CVE-2024-40782 6.5 - Medium - July 29, 2024

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

Dangling pointer

An out-of-bounds access issue was addressed with improved bounds checking

CVE-2024-40789 6.5 - Medium - July 29, 2024

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

This issue was addressed through improved state management

CVE-2024-40794 5.3 - Medium - July 29, 2024

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, Safari 17.6. Private Browsing tabs may be accessed without authentication.

A use-after-free issue was addressed with improved memory management

CVE-2024-40776 4.3 - Medium - July 29, 2024

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

Dangling pointer

An out-of-bounds read was addressed with improved bounds checking

CVE-2024-40779 5.5 - Medium - July 29, 2024

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

Out-of-bounds Read

An out-of-bounds read was addressed with improved bounds checking

CVE-2024-40780 5.5 - Medium - July 29, 2024

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to an unexpected process crash.

Out-of-bounds Read

This issue was addressed with improved checks

CVE-2024-40785 6.1 - Medium - July 29, 2024

This issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, Safari 17.6, iOS 17.6 and iPadOS 17.6, watchOS 10.6, tvOS 17.6, visionOS 1.3, macOS Sonoma 14.6. Processing maliciously crafted web content may lead to a cross site scripting attack.

XSS

The issue was addressed with improved UI handling

CVE-2024-40817 6.1 - Medium - July 29, 2024

The issue was addressed with improved UI handling. This issue is fixed in macOS Sonoma 14.6, Safari 17.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. Visiting a website that frames malicious content may lead to UI spoofing.

Clickjacking

The issue was addressed by adding additional logic

CVE-2024-27838 6.5 - Medium - June 10, 2024

The issue was addressed by adding additional logic. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.

The issue was addressed with improved checks

CVE-2024-27844 5.5 - Medium - June 10, 2024

The issue was addressed with improved checks. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5. A website's permission dialog may persist after navigation away from the site.

This issue was addressed with improvements to the noise injection algorithm

CVE-2024-27850 6.5 - Medium - June 10, 2024

This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in visionOS 1.2, macOS Sonoma 14.5, Safari 17.5, iOS 17.5 and iPadOS 17.5. A maliciously crafted webpage may be able to fingerprint the user.

The issue was addressed with improved bounds checks

CVE-2024-27851 8.8 - High - June 10, 2024

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing maliciously crafted web content may lead to arbitrary code execution.

Buffer Overflow

The issue was addressed with improved memory handling

CVE-2024-27808 8.8 - High - June 10, 2024

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling

CVE-2024-27820 8.8 - High - June 10, 2024

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. Processing web content may lead to arbitrary code execution.

This issue was addressed through improved state management

CVE-2024-27830 6.5 - Medium - June 10, 2024

This issue was addressed through improved state management. This issue is fixed in tvOS 17.5, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5, watchOS 10.5, macOS Sonoma 14.5. A maliciously crafted webpage may be able to fingerprint the user.

An integer overflow was addressed with improved input validation

CVE-2024-27833 8.8 - High - June 10, 2024

An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 17.5, iOS 16.7.8 and iPadOS 16.7.8, visionOS 1.2, Safari 17.5, iOS 17.5 and iPadOS 17.5. Processing maliciously crafted web content may lead to arbitrary code execution.

Integer Overflow or Wraparound

The issue was addressed with improved checks

CVE-2024-27834 5.5 - Medium - May 14, 2024

The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155

CVE-2024-4558 9.6 - Critical - May 07, 2024

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Dangling pointer

A logic issue was addressed with improved checks

CVE-2024-23271 6.5 - Medium - April 24, 2024

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, Safari 17.3, tvOS 17.3, macOS Sonoma 14.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.

A use after free issue was addressed with improved memory management

CVE-2023-42950 8.8 - High - March 28, 2024

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling

CVE-2023-42956 6.5 - Medium - March 28, 2024

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web content may lead to a denial-of-service.

A logic issue was addressed with improved validation

CVE-2024-23263 6.5 - Medium - March 08, 2024

A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

A logic issue was addressed with improved state management

CVE-2024-23284 6.5 - Medium - March 08, 2024

A logic issue was addressed with improved state management. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, iOS 16.7.6 and iPadOS 16.7.6, Safari 17.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

An injection issue was addressed with improved validation

CVE-2024-23280 6.5 - Medium - March 08, 2024

An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4, watchOS 10.4, tvOS 17.4. A maliciously crafted webpage may be able to fingerprint the user.

Injection

The issue was addressed with improved UI handling

CVE-2024-23254 6.5 - Medium - March 08, 2024

The issue was addressed with improved UI handling. This issue is fixed in tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 and iPadOS 17.4, watchOS 10.4, Safari 17.4. A malicious website may exfiltrate audio data cross-origin.

This issue was addressed through improved state management

CVE-2024-23273 4.3 - Medium - March 08, 2024

This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.

An inconsistent user interface issue was addressed with improved state management

CVE-2023-42843 4.3 - Medium - February 21, 2024

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

Authentication Bypass by Spoofing

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size

CVE-2024-1580 8.8 - High - February 19, 2024

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

Integer Overflow or Wraparound

The issue was addressed with improved memory handling

CVE-2024-23213 8.8 - High - January 23, 2024

The issue was addressed with improved memory handling. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. Processing web content may lead to arbitrary code execution.

An access issue was addressed with improved access restrictions

CVE-2024-23206 6.5 - Medium - January 23, 2024

An access issue was addressed with improved access restrictions. This issue is fixed in watchOS 10.3, tvOS 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. A maliciously crafted webpage may be able to fingerprint the user.

A type confusion issue was addressed with improved checks

CVE-2024-23222 8.8 - High - January 23, 2024

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited.

Object Type Confusion

A privacy issue was addressed with improved handling of user preferences

CVE-2024-23211 3.3 - Low - January 23, 2024

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in watchOS 10.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, Safari 17.3. A user's private browsing activity may be visible in Settings.

This issue was addressed by removing the vulnerable code

CVE-2023-40385 6.5 - Medium - January 10, 2024

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.

A use-after-free issue was addressed with improved memory management

CVE-2023-40414 9.8 - Critical - January 10, 2024

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 10, iOS 17 and iPadOS 17, tvOS 17, macOS Sonoma 14, Safari 17. Processing web content may lead to arbitrary code execution.

Dangling pointer

A correctness issue was addressed with improved checks

CVE-2023-42833 8.8 - High - January 10, 2024

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling

CVE-2023-42866 8.8 - High - January 10, 2024

The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

The issue was addressed with additional permissions checks

CVE-2023-42872 5.5 - Medium - January 10, 2024

The issue was addressed with additional permissions checks. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app may be able to access sensitive user data.

The issue was addressed with improved memory handling

CVE-2023-42883 5.5 - Medium - December 12, 2023

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, iOS 17.2 and iPadOS 17.2, watchOS 10.2, tvOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. Processing an image may lead to a denial-of-service.

The issue was addressed with improved memory handling

CVE-2023-42890 8.8 - High - December 12, 2023

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.

An out-of-bounds read was addressed with improved input validation

CVE-2023-42916 6.5 - Medium - November 30, 2023

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Out-of-bounds Read

A memory corruption vulnerability was addressed with improved locking

CVE-2023-42917 8.8 - High - November 30, 2023

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Memory Corruption

A logic issue was addressed with improved checks

CVE-2023-42852 8.8 - High - October 25, 2023

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling

CVE-2023-40447 8.8 - High - October 25, 2023

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.

Buffer Overflow

A use-after-free issue was addressed with improved memory management

CVE-2023-41976 8.8 - High - October 25, 2023

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.

Dangling pointer

The issue was addressed with improved memory handling

CVE-2023-41983 6.5 - Medium - October 25, 2023

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.

Buffer Overflow

A window management issue was addressed with improved state management

CVE-2023-40417 5.4 - Medium - September 27, 2023

A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.

The issue was addressed with improved checks

CVE-2023-41074 8.8 - High - September 27, 2023

The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.

This issue was addressed with improved iframe sandbox enforcement

CVE-2023-40451 8.8 - High - September 27, 2023

This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.

The issue was addressed with improved memory handling

CVE-2023-35074 8.8 - High - September 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved checks

CVE-2023-41993 8.8 - High - September 21, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Improper Check for Unusual or Exceptional Conditions

The issue was addressed with improved bounds checks

CVE-2022-48503 8.8 - High - August 14, 2023

The issue was addressed with improved bounds checks. This issue is fixed in tvOS 15.6, watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing web content may lead to arbitrary code execution.

This issue was addressed with improved checks

CVE-2023-32445 6.1 - Medium - July 28, 2023

This issue was addressed with improved checks. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. Processing a document may lead to a cross site scripting attack.

XSS

A logic issue was addressed with improved state management

CVE-2023-38599 6.5 - Medium - July 28, 2023

A logic issue was addressed with improved state management. This issue is fixed in Safari 16.6, watchOS 9.6, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A website may be able to track sensitive user information.

The issue was addressed with improved checks

CVE-2023-38572 7.5 - High - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. A website may be able to bypass Same Origin Policy.

The issue was addressed with improved checks

CVE-2023-38595 8.8 - High - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved checks

CVE-2023-38600 8.8 - High - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved memory handling

CVE-2023-38611 8.8 - High - July 27, 2023

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved checks

CVE-2023-37450 8.8 - High - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

The issue was addressed with improved checks

CVE-2023-38597 8.8 - High - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5, Safari 16.6. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved checks

CVE-2023-38594 8.8 - High - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.

The issue was addressed with improved checks

CVE-2023-38133 6.5 - Medium - July 27, 2023

The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may disclose sensitive information.

An out-of-bounds read was addressed with improved input validation

CVE-2023-28204 6.5 - Medium - June 23, 2023

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.

Out-of-bounds Read

An out-of-bounds read was addressed with improved input validation

CVE-2023-32402 6.5 - Medium - June 23, 2023

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.

Out-of-bounds Read

The issue was addressed with improved bounds checks

CVE-2023-32409 8.6 - High - June 23, 2023

The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.

A buffer overflow issue was addressed with improved memory handling

CVE-2023-32423 6.5 - Medium - June 23, 2023

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.

Classic Buffer Overflow

A memory corruption issue was addressed with improved state management

CVE-2023-32435 8.8 - High - June 23, 2023

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

Memory Corruption

A type confusion issue was addressed with improved checks

CVE-2023-32439 8.8 - High - June 23, 2023

A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Object Type Confusion

A use-after-free issue was addressed with improved memory management

CVE-2023-32373 8.8 - High - June 23, 2023

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Dangling pointer

This issue was addressed with improved state management

CVE-2023-27932 5.5 - Medium - May 08, 2023

This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, tvOS 16.4, watchOS 9.4. Processing maliciously crafted web content may bypass Same Origin Policy.

The issue was addressed by removing origin information

CVE-2023-27954 6.5 - Medium - May 08, 2023

The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.

This issue was addressed with improved state management

CVE-2023-28201 9.8 - Critical - May 08, 2023

This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution.

A memory corruption issue was addressed with improved validation

CVE-2022-32885 8.8 - High - May 08, 2023

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution

Memory Corruption

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apple macOS or by Apple? Click the Watch button to subscribe.

Apple
Vendor

Apple Safari
Product

subscribe