cbcvebase.
CVE-2023-40385
published 2024-01-10

CVE-2023-40385: This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be…

PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.60%
44.9th percentile
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.

Affected

10 ranges
VendorProductVersion rangeFixed in
appleios_17_and_ipados
appleios_and_ipados>= unspecified < 1717
appleipados< 17.017.0
appleiphone_os< 17.017.0
applemacos< 14.014.0
applemacos>= unspecified < 1414
applemacos_sonoma
applesafari< 17.017.0
applesafari
applesafari>= unspecified < 1717
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.