CVE-2024-23211
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2024-23211 is a privacy vulnerability discovered in Apple's Safari browser and related operating systems that was disclosed on January 22, 2024. The vulnerability affects multiple Apple products including Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, and watchOS 10.3. The issue allows a user's private browsing activity to be visible in Settings (Apple Support, NVD).

Technical details

The vulnerability is classified with a CVSS v3.1 Base Score of 3.3 (LOW) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N. The issue stems from improper handling of user preferences related to private browsing functionality. The vulnerability requires local access and user interaction to be exploited (NVD).

Impact

When exploited, the vulnerability allows unauthorized visibility of a user's private browsing activity through the Settings interface, potentially compromising user privacy and browsing confidentiality (Apple Support).

Mitigation and workarounds

Apple has addressed this privacy issue by improving the handling of user preferences in the following software updates: Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, iOS 16.7.5 and iPadOS 16.7.5, and watchOS 10.3. Users are recommended to update their devices to these versions to mitigate the vulnerability (Apple Support).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-43343CRITICAL9.8
  • Apple SafariApple Safari
  • libjavascriptcoregtk-4_1-0
NoYesSep 15, 2025
CVE-2025-43342CRITICAL9.8
  • Apple SafariApple Safari
  • webkit2gtk
NoYesSep 15, 2025
CVE-2025-43356MEDIUM6.5
  • Apple SafariApple Safari
  • webkitgtk4-devel
NoYesSep 15, 2025
CVE-2025-43327MEDIUM6.5
  • Apple SafariApple Safari
  • Safari
NoYesSep 15, 2025
CVE-2025-43368MEDIUM4.3
  • Apple SafariApple Safari
  • webkit2gtk3-devel
NoYesSep 15, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management