ZeroHour

CVE-2023-32409

KEVmass1

WebKit Sandbox Escape in Apple Safari, iOS, iPadOS, macOS, tvOS, and watchOS

CISA: Apple Multiple Products WebKit Sandbox Escape Vulnerability

CVSS 3.1
8.6 high
EPSS
17%p97
Published
()
KEV added
AI analysis

CVE-2023-32409 is a sandbox escape in Apple's WebKit browser engine, caused by insufficient bounds checking that was corrected in the May 2023 updates. It is triggered remotely when WebKit processes maliciously crafted web content, with no authentication or special user privileges required beyond loading attacker-controlled content (e.g., in Safari or any app rendering web views). A successful attacker breaks out of the Web Content sandbox, weakening the isolation between web content and the rest of the system and enabling further compromise of the device (CVSS assigns a high integrity impact). Anyone running Safari or iOS/iPadOS, macOS Ventura, tvOS, or watchOS versions before the fixed releases is affected, which covers essentially the entire unpatched Apple device base. Apple reports the issue may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22.

What to do: Apply the vendor updates per Apple's and CISA's required action: Safari 16.5, iOS/iPadOS 16.5 (or iOS/iPadOS 15.7.8 for users remaining on the iOS 15 branch), macOS Ventura 13.4, tvOS 16.5, and watchOS 9.5. Because WebKit renders web content for all iOS browsers and in-app web views, updating the OS is the primary mitigation; no workaround is documented. Federal agencies must patch within the KEV deadline and should verify fleet-wide OS and Safari versions.

Affected
Apple Safariversions prior to 16.5 (fixed in Safari 16.5)
Apple iOS (iPhone OS)versions prior to 16.5 and iOS 15 versions prior to 15.7.8 (fixed in iOS 16.5 and iOS 15.7.8)
Apple iPadOSversions prior to 16.5 and iPadOS 15 versions prior to 15.7.8 (fixed in iPadOS 16.5 and iPadOS 15.7.8)
Apple macOS (Ventura)versions prior to 13.4 (fixed in macOS Ventura 13.4)
Apple tvOSversions prior to 16.5 (fixed in tvOS 16.5)
Apple watchOSversions prior to 9.5 (fixed in watchOS 9.5)
Estimated exposure
mass≈1B+ Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch installed base; any device on a pre-fix build is exposed) — Apple has publicly reported an active installed base well above one billion devices, and the flaw affects WebKit across all of those platforms until the May 2023 fixes are applied, so exposure is on the order of the entire unpatched Apple…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos, tvos, watchos
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

In the news