The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
References
| Link | Resource |
|---|---|
| https://security.gentoo.org/glsa/202401-04 | Third Party Advisory |
| https://support.apple.com/en-us/HT213826 | Vendor Advisory |
| https://support.apple.com/en-us/HT213841 | Vendor Advisory |
| https://support.apple.com/en-us/HT213843 | Vendor Advisory |
| https://support.apple.com/en-us/HT213846 | Vendor Advisory |
| https://support.apple.com/en-us/HT213848 | Vendor Advisory |
| https://security.gentoo.org/glsa/202401-04 | Third Party Advisory |
| https://support.apple.com/en-us/HT213826 | Vendor Advisory |
| https://support.apple.com/en-us/HT213841 | Vendor Advisory |
| https://support.apple.com/en-us/HT213843 | Vendor Advisory |
| https://support.apple.com/en-us/HT213846 | Vendor Advisory |
| https://support.apple.com/en-us/HT213848 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-37450 | US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
23 Oct 2025, 18:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-37450 - US Government Resource |
21 Oct 2025, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Jan 2025, 16:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://support.apple.com/en-us/HT213826 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213841 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213843 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213846 - Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213848 - Vendor Advisory |
21 Nov 2024, 08:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://security.gentoo.org/glsa/202401-04 - Third Party Advisory | |
| References | () https://support.apple.com/en-us/HT213826 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213841 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213843 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213846 - Release Notes, Vendor Advisory | |
| References | () https://support.apple.com/en-us/HT213848 - Release Notes, Vendor Advisory |
27 Jun 2024, 18:51
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://security.gentoo.org/glsa/202401-04 - Third Party Advisory | |
| First Time |
Webkitgtk
Webkitgtk webkitgtk\+ |
|
| CPE | cpe:2.3:a:webkitgtk:webkitgtk\+:*:*:*:*:*:*:*:* |
05 Jan 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Aug 2023, 00:54
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://support.apple.com/en-us/HT213841 - Release Notes, Vendor Advisory | |
| References | (MISC) https://support.apple.com/en-us/HT213848 - Release Notes, Vendor Advisory | |
| References | (MISC) https://support.apple.com/en-us/HT213843 - Release Notes, Vendor Advisory | |
| References | (MISC) https://support.apple.com/en-us/HT213846 - Release Notes, Vendor Advisory | |
| References | (MISC) https://support.apple.com/en-us/HT213826 - Release Notes, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CPE | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo |
27 Jul 2023, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-07-27 00:15
Updated : 2025-10-23 18:48
NVD link : CVE-2023-37450
Mitre link : CVE-2023-37450
CVE.ORG link : CVE-2023-37450
JSON object : View
Products Affected
apple
- tvos
- ipados
- safari
- macos
- watchos
- iphone_os
webkitgtk
- webkitgtk\+
CWE
