CVE-2023-32373
KEVmassWebKit Use-After-Free Zero-Day in Apple iOS, Safari, macOS Enables Code Execution
CISA: Apple Multiple Products WebKit Use-After-Free Vulnerability
CVE-2023-32373 is a use-after-free memory-corruption flaw (CWE-416) in WebKit, the web-content engine used across Apple's platforms. It is triggered when an affected device processes maliciously crafted web content, such as a hostile webpage or embedded web view, and requires user interaction. A successful attacker gains arbitrary code execution on the victim device, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). All products shipping vulnerable WebKit are exposed, including iPhone, iPad, Mac (Ventura), Apple Watch, Apple TV, and Safari, plus WebKitGTK-based packages such as those in Red Hat Enterprise Linux. Apple reports the flaw may have been actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22, and fixes shipped in iOS/iPadOS 16.5 and 15.7.6, macOS Ventura 13.4, Safari 16.5, watchOS 9.5, and tvOS 16.5.
What to do: Upgrade to the fixed releases: iOS/iPadOS 16.5 (or 15.7.6 on older devices), macOS Ventura 13.4, Safari 16.5, watchOS 9.5, and tvOS 16.5, and apply Red Hat's updated WebKitGTK packages on affected Linux systems. Because the flaw is in CISA's KEV catalog and reported as actively exploited, federal agencies and prioritized defenders should patch by the KEV deadline. Users who cannot update immediately should avoid browsing untrusted web content, and admins should verify installed OS and Safari versions against the fixed releases.
| Apple Safari | versions prior to 16.5 |
| Apple iOS / iPhone OS | versions prior to 16.5 and the 15.x line prior to 15.7.6 |
| Apple iPadOS | versions prior to 16.5 and the 15.x line prior to 15.7.6 |
| Apple macOS (Ventura) | macOS Ventura versions prior to 13.4 |
| Apple watchOS | versions prior to 9.5 |
| Apple tvOS | versions prior to 16.5 |
| WebKitGTK | — |
| Red Hat Enterprise Linux (WebKitGTK packages) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown