ZeroHour

CVE-2023-28205

KEVmass

Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CISA: Apple Multiple Products WebKit Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
27%p98
Published
()
KEV added
AI analysis

CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile).

What to do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content.

Affected
Apple iOS
Apple iPadOS
Apple macOS
Apple Safari
Apple WebKit
non-Apple products relying on WebKit for HTML processing (e.g., HTML parsers)
Estimated exposure
mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari) — WebKit ships as the system web/HTML engine on all Apple platforms, so exposure scales with Apple's global installed base of hundreds of millions to billions of active iOS, iPadOS, and macOS devices and Safari users, plus non-Apple WebKit…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news