CVE-2024-23271: Apple iPadOS
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.
Affected products
- Apple iPadOS: before 17.3 (fixed in 17.3)
- Apple iPhone OS: before 17.3 (fixed in 17.3)
- Apple macOS: from 14.0, before 14.3 (fixed in 14.3)
- Apple Safari: before 17.3 (fixed in 17.3)
- Apple tvOS: before 17.3 (fixed in 17.3)
- Apple watchOS: before 10.3 (fixed in 10.3)
Published 2024-04-24. Last modified 2026-06-17.