CVE-2024-23273

This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing tabs may be accessed without authentication.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:57

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2024/Mar/20 - Mailing List () http://seclists.org/fulldisclosure/2024/Mar/20 - Mailing List
References () http://seclists.org/fulldisclosure/2024/Mar/21 - Mailing List () http://seclists.org/fulldisclosure/2024/Mar/21 - Mailing List
References () https://support.apple.com/en-us/HT214081 - Vendor Advisory () https://support.apple.com/en-us/HT214081 - Vendor Advisory
References () https://support.apple.com/en-us/HT214084 - Vendor Advisory () https://support.apple.com/en-us/HT214084 - Vendor Advisory
References () https://support.apple.com/en-us/HT214089 - Vendor Advisory () https://support.apple.com/en-us/HT214089 - Vendor Advisory

30 Oct 2024, 20:35

Type Values Removed Values Added
CWE CWE-295

14 Mar 2024, 19:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Apple iphone Os
Apple macos
Apple
Apple ipad Os
Apple safari
CPE cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () http://seclists.org/fulldisclosure/2024/Mar/21 - () http://seclists.org/fulldisclosure/2024/Mar/21 - Mailing List
References () https://support.apple.com/en-us/HT214084 - () https://support.apple.com/en-us/HT214084 - Vendor Advisory
References () https://support.apple.com/en-us/HT214089 - () https://support.apple.com/en-us/HT214089 - Vendor Advisory
References () http://seclists.org/fulldisclosure/2024/Mar/20 - () http://seclists.org/fulldisclosure/2024/Mar/20 - Mailing List
References () https://support.apple.com/en-us/HT214081 - () https://support.apple.com/en-us/HT214081 - Vendor Advisory

13 Mar 2024, 21:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Mar/21 -
  • () http://seclists.org/fulldisclosure/2024/Mar/20 -

08 Mar 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-08 02:15

Updated : 2024-11-21 08:57


NVD link : CVE-2024-23273

Mitre link : CVE-2024-23273

CVE.ORG link : CVE-2024-23273


JSON object : View

Products Affected

apple

  • ipad_os
  • iphone_os
  • macos
  • safari
CWE
NVD-CWE-noinfo CWE-295

Improper Certificate Validation