CVE-2023-42923

MEDIUM

iPadOS < 17.2 - Unauthenticated Private Browsing Tab Access

Title source: llm
STIX 2.1

Description

This issue was addressed through improved state management. This issue is fixed in iOS 17.2 and iPadOS 17.2. Private Browsing tabs may be accessed without authentication.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2023/Dec/7
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT214035

Scores

CVSS v3 5.3
EPSS 0.0023
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (2)
apple/ipados < 17.2
apple/iphone_os < 17.2
Published Dec 12, 2023
Tracked Since Feb 18, 2026