ZeroHour

CVE-2023-32373

KEVmass

WebKit Use-After-Free Zero-Day in Apple iOS, Safari, macOS Enables Code Execution

CISA: Apple Multiple Products WebKit Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
12%p96
Published
()
KEV added
AI analysis

CVE-2023-32373 is a use-after-free memory-corruption flaw (CWE-416) in WebKit, the web-content engine used across Apple's platforms. It is triggered when an affected device processes maliciously crafted web content, such as a hostile webpage or embedded web view, and requires user interaction. A successful attacker gains arbitrary code execution on the victim device, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). All products shipping vulnerable WebKit are exposed, including iPhone, iPad, Mac (Ventura), Apple Watch, Apple TV, and Safari, plus WebKitGTK-based packages such as those in Red Hat Enterprise Linux. Apple reports the flaw may have been actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22, and fixes shipped in iOS/iPadOS 16.5 and 15.7.6, macOS Ventura 13.4, Safari 16.5, watchOS 9.5, and tvOS 16.5.

What to do: Upgrade to the fixed releases: iOS/iPadOS 16.5 (or 15.7.6 on older devices), macOS Ventura 13.4, Safari 16.5, watchOS 9.5, and tvOS 16.5, and apply Red Hat's updated WebKitGTK packages on affected Linux systems. Because the flaw is in CISA's KEV catalog and reported as actively exploited, federal agencies and prioritized defenders should patch by the KEV deadline. Users who cannot update immediately should avoid browsing untrusted web content, and admins should verify installed OS and Safari versions against the fixed releases.

Affected
Apple Safariversions prior to 16.5
Apple iOS / iPhone OSversions prior to 16.5 and the 15.x line prior to 15.7.6
Apple iPadOSversions prior to 16.5 and the 15.x line prior to 15.7.6
Apple macOS (Ventura)macOS Ventura versions prior to 13.4
Apple watchOSversions prior to 9.5
Apple tvOSversions prior to 16.5
WebKitGTK
Red Hat Enterprise Linux (WebKitGTK packages)
Estimated exposure
mass≈1 billion+ Apple devices and Safari installations (essentially the entire unpatched Apple installed base) — WebKit renders all web content on iOS, iPadOS, watchOS, and tvOS and powers Safari on macOS, and Apple's active device installed base exceeds a billion, so any device not yet on the fixed releases is plausibly exposed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
appleredhatwebkitgtk
Products
safari, ipados, iphone os, macos, tvos, watchos, enterprise linux, webkitgtk\+
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news