===================================================================== CERT-Renater Note d'Information No. 2024/VULN061 _____________________________________________________________________ DATE : 25/01/2024 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Safari versions prior to 17.3. ===================================================================== https://support.apple.com/kb/HT214056 _____________________________________________________________________ APPLE-SA-01-22-2024-1 Safari 17.3 Safari 17.3 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT214056. Apple maintains a Security Updates page at https://support.apple.com/HT201222 which lists recent software updates with security advisories. Safari Available for: macOS Monterey and macOS Ventura Impact: A user's private browsing activity may be visible in Settings Description: A privacy issue was addressed with improved handling of user preferences. CVE-2024-23211: Mark Bowers WebKit Available for: macOS Monterey and macOS Ventura Impact: A maliciously crafted webpage may be able to fingerprint the user Description: An access issue was addressed with improved access restrictions. WebKit Bugzilla: 262699 CVE-2024-23206: an anonymous researcher WebKit Available for: macOS Monterey and macOS Ventura Impact: Processing web content may lead to arbitrary code execution Description: The issue was addressed with improved memory handling. WebKit Bugzilla: 266619 CVE-2024-23213: Wangtaiyu of Zhongfu info WebKit Available for: macOS Monterey and macOS Ventura Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited. Description: A type confusion issue was addressed with improved checks. WebKit Bugzilla: 267134 CVE-2024-23222 Safari 17.3 may be obtained from the Mac App Store. All information is also posted on the Apple Security Updates web site: https://support.apple.com/en-us/HT201222. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================