« Volver al listado

CVE-2024-23263

Estado: ModificadaMedia (6.5)—

A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (10)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-23263",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-23263",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-18T04:00:44.910447Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "Safari",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.4",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "iOS and iPadOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "16.7.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.4",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "macOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "14.4",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "tvOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.4",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "visionOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "watchOS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "10.4",
              "versionType": "custom"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:apple:visionos:-:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "visionos",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.1",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:tvos:-:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "tvos",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:iphone_os:16.7:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "iphone_os",
          "versions": [
            {
              "status": "affected",
              "version": "16.7",
              "lessThan": "16.7.6",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:ipad_os:16.7:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "ipad_os",
          "versions": [
            {
              "status": "affected",
              "version": "16.7",
              "lessThan": "16.7.6",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "iphone_os",
          "versions": [
            {
              "status": "affected",
              "version": "17.0",
              "lessThan": "17.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:ipad_os:17.0:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "ipad_os",
          "versions": [
            {
              "status": "affected",
              "version": "17.0",
              "lessThan": "17.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:macos:14.0:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "macos",
          "versions": [
            {
              "status": "affected",
              "version": "14.0",
              "lessThan": "14.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "watchos",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "10.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*"
          ],
          "vendor": "webkitgtk",
          "product": "webkitgtk",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2.45.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:2.3:a:apple:safari:-:*:*:*:*:*:*:*"
          ],
          "vendor": "apple",
          "product": "safari",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "17.4",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-03-08T02:15:48.980",
  "references": [
    {
      "url": "https://support.apple.com/en-us/120880",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120881",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120882",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120883",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120893",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120894",
      "source": "product-security@apple.com"
    },
    {
      "url": "https://support.apple.com/en-us/120895",
      "source": "product-security@apple.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/20",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/21",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/24",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/25",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Mar/26",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/03/26/1",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AO4BNNL5X2LQBJ6WX7VT4SGMA6R7DUU5/",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAIPBVDQV3GHMSNSZNEJCRZEPM7BEYGF/",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IXLXIOAH5S7J22LJTCIAVFVVJ4TESAX4/",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXORDRCSQAQU436W4S2Z3X5B5PDXL3LI/",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214081",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214082",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214084",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214086",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214087",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214088",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/en-us/HT214089",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214081",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214082",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214084",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214087",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT214089",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced."
    },
    {
      "lang": "es",
      "value": "Se abordó un problema de lógica con una validación mejorada. Este problema se solucionó en tvOS 17.4, macOS Sonoma 14.4, visionOS 1.1, iOS 17.4 y iPadOS 17.4, watchOS 10.4, iOS 16.7.6 y iPadOS 16.7.6, Safari 17.4. El procesamiento de contenido web creado con fines malintencionados puede impedir que se aplique la Política de seguridad de contenido."
    }
  ],
  "lastModified": "2026-06-17T07:12:26.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC7753BA-5DF8-4F98-8DA8-69DA473F8307",
              "versionEndExcluding": "17.4"
            },
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9277B3E8-4519-4E07-A89A-A08C604AB78C",
              "versionEndExcluding": "16.7.6"
            },
            {
              "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CB78D53-5EC0-45E5-871B-0C18F1E6D438",
              "versionEndExcluding": "17.4",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AF8B925-3DE5-4CC8-A4C3-95D8F107D607",
              "versionEndExcluding": "16.7.6"
            },
            {
              "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2FE8515-300C-4B6F-92A0-7D1E6D93F907",
              "versionEndExcluding": "17.4",
              "versionStartIncluding": "17.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73160D1F-755B-46D2-969F-DF8E43BB1099",
              "versionEndExcluding": "14.4",
              "versionStartIncluding": "14.0"
            },
            {
              "criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB6BA6CB-001B-4440-A9AE-473F5722F8E0",
              "versionEndExcluding": "17.4"
            },
            {
              "criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB7F6CDA-FEC0-45D7-ACBE-8B5AD35F1AB5",
              "versionEndExcluding": "1.1"
            },
            {
              "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5547F484-4E4B-4961-BAF8-F891D50BB4B6",
              "versionEndExcluding": "10.4"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:webkitgtk:webkitgtk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF5BDB2C-7F5F-41B4-87C4-C4B938C7D317",
              "versionEndExcluding": "2.44.0"
            },
            {
              "criteria": "cpe:2.3:a:wpewebkit:wpe_webkit:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "336F9990-F267-4013-8353-5AA10039C515",
              "versionEndExcluding": "2.44.0"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC559B26-5DFC-4B7A-A27C-B77DE755DFF9"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"
            },
            {
              "criteria": "cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA277A6C-83EC-4536-9125-97B84C4FAF59"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}