ZeroHour

CVE-2023-32435

KEVmass1

Memory Corruption in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CISA: Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
23%p98
Published
()
KEV added
AI analysis

CVE-2023-32435 is an out-of-bounds write (CWE-787) memory corruption flaw in the WebKit engine shipped with Apple Safari, iOS, iPadOS, and macOS. It is triggered when WebKit processes maliciously crafted web content, such as a hostile webpage or embedded HTML, and successful exploitation leads to arbitrary code execution. Because WebKit is also used by non-Apple HTML parsers and applications, the impact extends beyond Safari and Apple's own browsers. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-06-23, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. EPSS estimates a 22.8% probability of exploitation in the next 30 days (98th percentile), and a CVSS score is not yet published.

What to do: Update Safari to 16.5 or later, iOS/iPadOS to 16.5 (or 15.7.6 on the legacy branch) or later, and macOS to the patched Ventura/Monterey/Big Sur releases (13.4 / 12.6.6 / 11.7.7) or later, then verify managed fleets are on fixed builds per the CISA KEV required action. Prioritize internet-exposed and high-risk users, since the flaw is confirmed exploited in the wild. If you ship or operate non-Apple products that embed WebKit, pull the fixed WebKit from the upstream project or your vendor.

Affected
Apple SafariVersions prior to the WebKit fix shipped in Safari 16.5 (May 2023; see Apple advisory for exact ranges)
Apple iOSVersions prior to iOS 16.5 and the iOS 15.7.6 legacy-branch update
Apple iPadOSVersions prior to iPadOS 16.5 and the iPadOS 15.7.6 legacy-branch update
Apple macOSVersions prior to the macOS updates that carry the fixed WebKit (Ventura, Monterey, and Big Sur branches)
Apple WebKit (affects multiple products, including non-Apple HTML parsers that use WebKit)All builds prior to the May 2023 WebKit fixes
Estimated exposure
mass>1,000,000,000 devices/users (WebKit is the system HTML engine on every iPhone and iPad and powers Safari on macOS) — WebKit ships as the default browser/HTML engine on all iOS, iPadOS, and macOS devices — an active Apple installed base well over 1 billion — so every unpatched device is plausibly affected, with an unknown subset of non-Apple WebKit…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news