---
id: CVE-2023-41074
title: The issue was addressed with improved checks
summary: >-
  The issue was addressed with improved checks. This issue is fixed in tvOS 17,
  Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web
  content may lead to arbitrary code execution.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: apple
product: safari
affected:
  - safari < 17.0
  - ipados < 17.0
  - iphone_os < 17.0
  - macos < 14.0
  - tvos < 17.0
  - watchos < 10.0
  - debian_linux = 11.0
  - debian_linux = 12.0
  - fedora = 37
patched:
  - safari 17.0
  - ipados 17.0
  - iphone_os 17.0
  - macos 14.0
  - tvos 17.0
  - watchos 10.0
published: '2023-09-27'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:44.153'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-41074'
references:
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/10'
    label: product-security@apple.com
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/2'
    label: product-security@apple.com
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/3'
    label: product-security@apple.com
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/8'
    label: product-security@apple.com
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/9'
    label: product-security@apple.com
  - url: 'http://www.openwall.com/lists/oss-security/2023/09/28/3'
    label: product-security@apple.com
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/
    label: product-security@apple.com
  - url: 'https://security.gentoo.org/glsa/202401-33'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/HT213936'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/HT213937'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/HT213938'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/HT213940'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/HT213941'
    label: product-security@apple.com
  - url: 'https://www.debian.org/security/2023/dsa-5527'
    label: product-security@apple.com
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/10'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/8'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2023/Oct/9'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2023/09/28/3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EEMDC5TQAANFH5D77QM34ZTUKXPFGVL/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202401-33'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/en-us/HT213936'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/en-us/HT213937'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/en-us/HT213938'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/en-us/HT213940'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://support.apple.com/en-us/HT213941'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://webkitgtk.org/security/WSA-2023-0009.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2023/dsa-5527'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-06-03T16:02:12.442548Z'
epss: 0.03914
epssPercentile: 0.90024
ingestedAt: '2026-10-07T16:38:22.252Z'
---

## Overview

The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.

## Affected

- `safari < 17.0`
- `ipados < 17.0`
- `iphone_os < 17.0`
- `macos < 14.0`
- `tvos < 17.0`
- `watchos < 10.0`
- `debian_linux = 11.0`
- `debian_linux = 12.0`
- `fedora = 37`

## Remediation

Upgrade past the affected range:

- `safari 17.0`
- `ipados 17.0`
- `iphone_os 17.0`
- `macos 14.0`
- `tvos 17.0`
- `watchos 10.0`
