This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213941 | vendor advisory |
http://www.openwall.com/lists/oss-security/2023/09/28/3 | mailing list |
http://seclists.org/fulldisclosure/2023/Oct/2 | third party advisory mailing list |
https://security.gentoo.org/glsa/202401-33 | |
https://webkitgtk.org/security/WSA-2023-0009.html |