CVE-2023-42843Authentication Bypass by Spoofing in Apple IOS AND Ipados

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 72.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21
Latest updateApr 15

Description

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages9 packages

NVDapple/ipad_os17.017.1+1
CVEListV5apple/ios_and_ipadosunspecified16.7+1
CVEListV5apple/macosunspecified14.1
CVEListV5apple/safariunspecified17.1
NVDapple/safari< 17.1

Also affects: Fedora 40

🔴Vulnerability Details

3
OSV
CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management2024-02-21
GHSA
GHSA-2c3h-gr5x-3fh2: An inconsistent user interface issue was addressed with improved state management2024-02-21
CVEList
CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management2024-02-21

📋Vendor Advisories

7
Ubuntu
WebKitGTK vulnerabilities2024-04-15
Red Hat
webkit: visiting a malicious website may lead to address bar spoofing2024-03-08
Apple
CVE-2023-42843: macOS Sonoma 14.12023-10-25
Apple
CVE-2023-42843: iOS 17.1 and iPadOS 17.12023-10-25
Apple
CVE-2023-42843: Safari 17.12023-10-25