CVE-2023-28201

This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

29 Jan 2025, 19:15

Type Values Removed Values Added
CWE CWE-362

12 Dec 2024, 14:26

Type Values Removed Values Added
First Time Apple ipados
CPE cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*

21 Nov 2024, 07:54

Type Values Removed Values Added
References () https://support.apple.com/en-us/HT213670 - Vendor Advisory () https://support.apple.com/en-us/HT213670 - Vendor Advisory
References () https://support.apple.com/en-us/HT213671 - Vendor Advisory () https://support.apple.com/en-us/HT213671 - Vendor Advisory
References () https://support.apple.com/en-us/HT213673 - Vendor Advisory () https://support.apple.com/en-us/HT213673 - Vendor Advisory
References () https://support.apple.com/en-us/HT213674 - () https://support.apple.com/en-us/HT213674 -
References () https://support.apple.com/en-us/HT213676 - Vendor Advisory () https://support.apple.com/en-us/HT213676 - Vendor Advisory

27 Jul 2023, 04:15

Type Values Removed Values Added
Summary This issue was addressed with improved state management. This issue is fixed in Safari 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. A remote user may be able to cause unexpected app termination or arbitrary code execution This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution.
References
  • {'url': 'https://support.apple.com/kb/HT213674', 'name': 'https://support.apple.com/kb/HT213674', 'tags': [], 'refsource': 'CONFIRM'}
  • (MISC) https://support.apple.com/en-us/HT213674 -

09 Jun 2023, 00:15

Type Values Removed Values Added
References
  • (CONFIRM) https://support.apple.com/kb/HT213674 -

19 May 2023, 16:15

Type Values Removed Values Added
Summary This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary code execution This issue was addressed with improved state management. This issue is fixed in Safari 16.4, iOS 15.7.4 and iPadOS 15.7.4, iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. A remote user may be able to cause unexpected app termination or arbitrary code execution

15 May 2023, 13:24

Type Values Removed Values Added
References (MISC) https://support.apple.com/en-us/HT213673 - (MISC) https://support.apple.com/en-us/HT213673 - Vendor Advisory
References (MISC) https://support.apple.com/en-us/HT213671 - (MISC) https://support.apple.com/en-us/HT213671 - Vendor Advisory
References (MISC) https://support.apple.com/en-us/HT213670 - (MISC) https://support.apple.com/en-us/HT213670 - Vendor Advisory
References (MISC) https://support.apple.com/en-us/HT213676 - (MISC) https://support.apple.com/en-us/HT213676 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
First Time Apple iphone Os
Apple ipad Os
Apple safari
Apple macos
Apple
CWE NVD-CWE-noinfo

08 May 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-08 20:15

Updated : 2025-01-29 19:15


NVD link : CVE-2023-28201

Mitre link : CVE-2023-28201

CVE.ORG link : CVE-2023-28201


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
  • macos
  • safari
CWE
NVD-CWE-noinfo CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')