CVE-2023-32409
KEVmass1WebKit Sandbox Escape in Apple Safari, iOS, iPadOS, macOS, tvOS, and watchOS
CISA: Apple Multiple Products WebKit Sandbox Escape Vulnerability
CVE-2023-32409 is a sandbox escape in Apple's WebKit browser engine, caused by insufficient bounds checking that was corrected in the May 2023 updates. It is triggered remotely when WebKit processes maliciously crafted web content, with no authentication or special user privileges required beyond loading attacker-controlled content (e.g., in Safari or any app rendering web views). A successful attacker breaks out of the Web Content sandbox, weakening the isolation between web content and the rest of the system and enabling further compromise of the device (CVSS assigns a high integrity impact). Anyone running Safari or iOS/iPadOS, macOS Ventura, tvOS, or watchOS versions before the fixed releases is affected, which covers essentially the entire unpatched Apple device base. Apple reports the issue may have been actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22.
What to do: Apply the vendor updates per Apple's and CISA's required action: Safari 16.5, iOS/iPadOS 16.5 (or iOS/iPadOS 15.7.8 for users remaining on the iOS 15 branch), macOS Ventura 13.4, tvOS 16.5, and watchOS 9.5. Because WebKit renders web content for all iOS browsers and in-app web views, updating the OS is the primary mitigation; no workaround is documented. Federal agencies must patch within the KEV deadline and should verify fleet-wide OS and Safari versions.
| Apple Safari | versions prior to 16.5 (fixed in Safari 16.5) |
| Apple iOS (iPhone OS) | versions prior to 16.5 and iOS 15 versions prior to 15.7.8 (fixed in iOS 16.5 and iOS 15.7.8) |
| Apple iPadOS | versions prior to 16.5 and iPadOS 15 versions prior to 15.7.8 (fixed in iPadOS 16.5 and iPadOS 15.7.8) |
| Apple macOS (Ventura) | versions prior to 13.4 (fixed in macOS Ventura 13.4) |
| Apple tvOS | versions prior to 16.5 (fixed in tvOS 16.5) |
| Apple watchOS | versions prior to 9.5 (fixed in watchOS 9.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- safari, ipados, iphone os, macos, tvos, watchos
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N