CVE-2023-40451: Use After Free
An attacker with JavaScript execution may be able to execute arbitrary code. This issue was addressed with improved iframe sandbox enforcement.
Reference: https://webkitgtk.org/security/WSA-2023-0009.html#CVE-2023-40451
Other sources
Safari. A window management issue was addressed with improved state management.
— Apple
This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
— MITRE
WebKit. A correctness issue was addressed with improved checks.
— Apple
WebKit. A use-after-free issue was addressed with improved memory management.
— Apple
WebKit. This issue was addressed by removing the vulnerable code.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue in WebKit?
The vulnerability ID for this issue in WebKit is CVE-2023-40451.
How was this issue addressed?
This issue was addressed with improved iframe sandbox enforcement.
Which software is affected by this vulnerability?
The Apple Safari browser version up to but excluding 17 is affected by this vulnerability.
How can I fix this vulnerability?
To fix this vulnerability, update your Apple Safari browser to version 17 or newer.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found on Apple's support page: https://support.apple.com/en-us/HT213941