This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in Safari 17. An attacker with JavaScript execution may be able to execute arbitrary code.
2023-09-27T15:19:17.090
2024-11-21T08:19:29.647
Modified
CVSSv3.1: 8.8 (HIGH)