CVE-2023-28204
KEVmassActively Exploited Out-of-Bounds Read in Apple WebKit (CVE-2023-28204)
CISA: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
An out-of-bounds read (CWE-125) in Apple's WebKit browser engine failed to properly validate inputs when processing web content, potentially exposing sensitive information from a device's memory. An attacker can trigger it by getting a user to process maliciously crafted web content — for example viewing a hostile webpage in Safari or in an app that renders web content — as exploitation requires user interaction but no privileges. The impact is information disclosure only (CVSS rates high confidentiality impact, with no integrity or availability impact), which can still leak data useful for follow-on attacks. Everyone relying on WebKit-based rendering is affected: Safari users, and users of iPhones, iPads, Macs (Ventura), Apple TVs, and Apple Watches, plus WebKitGTK users on Linux. Apple acknowledged reports of active exploitation, CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-05-22, and fixes shipped in May 2023 (watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS/iPadOS 16.5 or 15.7.6, Safari 16.5).
What to do: Upgrade iPhone/iPad to iOS/iPadOS 16.5 (or 15.7.6 on the iOS 15 line), Safari to 16.5, macOS Ventura to 13.4, tvOS to 16.5, and watchOS to 9.5; on Linux, install the latest patched WebKitGTK package via your distribution. Because the flaw is confirmed exploited in the wild and only requires a user to view attacker-controlled web content, treat patching as urgent and verify endpoints report the fixed versions. CISA's required action is to apply updates per vendor instructions.
| apple Safari | all versions prior to 16.5 |
| apple iPhone OS (iOS) | all versions prior to 16.5; iOS 15 branch prior to 15.7.6 |
| apple iPadOS | all versions prior to 16.5; iPadOS 15 branch prior to 15.7.6 |
| apple macOS (Ventura) | all versions prior to 13.4 |
| apple tvOS | all versions prior to 16.5 |
| apple watchOS | all versions prior to 9.5 |
| WebKitGTK | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown