CVE-2023-40417: Apple iPadOS
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
A window management issue was addressed with improved state management. This issue is fixed in Safari 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. Visiting a website that frames malicious content may lead to UI spoofing.
Affected products
- Apple iPadOS: before 17.0 (fixed in 17.0)
- Apple iPhone OS: before 17.0 (fixed in 17.0)
- Apple macOS: before 14.0 (fixed in 14.0)
- Apple Safari: before 17.0 (fixed in 17.0)
- Apple watchOS: before 10.0 (fixed in 10.0)
Published 2023-09-27. Last modified 2026-06-17.