CVE-2024-23271: Apple iPadOS

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A malicious website may cause unexpected cross-origin behavior.

Affected products

  • Apple iPadOS: before 17.3 (fixed in 17.3)
  • Apple iPhone OS: before 17.3 (fixed in 17.3)
  • Apple macOS: from 14.0, before 14.3 (fixed in 14.3)
  • Apple Safari: before 17.3 (fixed in 17.3)
  • Apple tvOS: before 17.3 (fixed in 17.3)
  • Apple watchOS: before 10.3 (fixed in 10.3)

Published 2024-04-24. Last modified 2026-06-17.