Medium severity5.4NVD Advisory· Published Sep 27, 2023· Updated Jun 17, 2026
CVE-2023-40417
CVE-2023-40417
Description
A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*range: <17.0
- (no CPE)range: 17
- (no CPE)range: unspecified
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <17.0
- (no CPE)range: 17
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: <14.0
- (no CPE)range: Sonoma 14
- (no CPE)range: unspecified
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*range: <10.0
- (no CPE)range: 10
- (no CPE)range: unspecified
- Range: 17
- Range: unspecified
Patches
Vulnerability mechanics
References
11- seclists.org/fulldisclosure/2023/Oct/2nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2023/Oct/3nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2023/Oct/8nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2023/Oct/9nvdMailing ListThird Party Advisory
- support.apple.com/en-us/HT213937nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213938nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213940nvdRelease NotesVendor Advisory
- support.apple.com/en-us/HT213941nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT213937nvd
- support.apple.com/kb/HT213938nvd
- support.apple.com/kb/HT213941nvd
News mentions
0No linked articles in our index yet.