CVE Vulnerabilities

CVE-2023-40385

Published: Jan 10, 2024 | Modified: Jun 17, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. A remote attacker may be able to view leaked DNS queries with Private Relay turned on.

Affected Software

NameVendorStart VersionEnd Version
SafariApple*17.0 (excluding)
IpadosApple*17.0 (excluding)
Iphone_osApple*17.0 (excluding)
MacosApple*14.0 (excluding)

References