CVE-2023-42843 — Authentication Bypass by Spoofing in Apple IOS AND Ipados
Severity
4.3MEDIUMNVD
EPSS
0.1%
top 72.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 21
Latest updateApr 15
Description
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages9 packages
Also affects: Fedora 40
🔴Vulnerability Details
3OSV▶
CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management↗2024-02-21
GHSA▶
GHSA-2c3h-gr5x-3fh2: An inconsistent user interface issue was addressed with improved state management↗2024-02-21
CVEList▶
CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management↗2024-02-21