VDB
DEBIAN-CVE-2023-27954
DEBIAN-CVE-2023-27954
PUBLISHED
CVSS 6.5 MEDIUM
The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:12 | webkit2gtk | 0, 0, 0 |
| Debian:11 | webkit2gtk | 2.36.7-1~deb11u1, 2.38.0-1, 2.38.0-1~deb10u1 |
| Debian:13 | webkit2gtk | 0, 0, 0 |
| Debian:11 | wpewebkit | 2.36.7-1, 2.38.5-1, 2.38.5-1~deb11u1 |
| Debian:14 | webkit2gtk | 0, 0, 0 |
| Debian:13 | wpewebkit | 0, 0, 0 |
| Debian:12 | wpewebkit | 0, 0, 0 |
| Debian:14 | wpewebkit | 0, 0, 0 |
Exploit Intelligence
- macos_v2_generated.go (github-poc)
- macos_v1_generated.go (github-poc)
Timeline
- May 8, 2023 CVE Published
- Apr 28, 2026 CVE Updated