
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-40397 is a security vulnerability discovered in WebKit that was fixed in macOS Ventura 13.5 and WebKitGTK/WPE WebKit versions before 2.40.5. The vulnerability allows a remote attacker to cause arbitrary JavaScript code execution (Apple Advisory, WebKit Advisory).
The vulnerability was addressed by implementing improved checks in the WebKit engine. It received a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network attack vector, low attack complexity, no privileges required, no user interaction needed, and high impact on confidentiality, integrity and availability (NVD).
The vulnerability allows remote attackers to execute arbitrary JavaScript code, potentially leading to complete compromise of the affected system. The high CVSS score indicates severe potential impact on system confidentiality, integrity, and availability (NVD).
The vulnerability has been patched in macOS Ventura 13.5 and WebKitGTK/WPE WebKit version 2.40.5. Users are strongly recommended to update to these or later versions to mitigate the risk (Apple Advisory, WebKit Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."