CVE-2023-32435
KEVmass1Memory Corruption in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution
CISA: Apple Multiple Products WebKit Memory Corruption Vulnerability
CVE-2023-32435 is an out-of-bounds write (CWE-787) memory corruption flaw in the WebKit engine shipped with Apple Safari, iOS, iPadOS, and macOS. It is triggered when WebKit processes maliciously crafted web content, such as a hostile webpage or embedded HTML, and successful exploitation leads to arbitrary code execution. Because WebKit is also used by non-Apple HTML parsers and applications, the impact extends beyond Safari and Apple's own browsers. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-06-23, confirming exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is known. EPSS estimates a 22.8% probability of exploitation in the next 30 days (98th percentile), and a CVSS score is not yet published.
What to do: Update Safari to 16.5 or later, iOS/iPadOS to 16.5 (or 15.7.6 on the legacy branch) or later, and macOS to the patched Ventura/Monterey/Big Sur releases (13.4 / 12.6.6 / 11.7.7) or later, then verify managed fleets are on fixed builds per the CISA KEV required action. Prioritize internet-exposed and high-risk users, since the flaw is confirmed exploited in the wild. If you ship or operate non-Apple products that embed WebKit, pull the fixed WebKit from the upstream project or your vendor.
| Apple Safari | Versions prior to the WebKit fix shipped in Safari 16.5 (May 2023; see Apple advisory for exact ranges) |
| Apple iOS | Versions prior to iOS 16.5 and the iOS 15.7.6 legacy-branch update |
| Apple iPadOS | Versions prior to iPadOS 16.5 and the iPadOS 15.7.6 legacy-branch update |
| Apple macOS | Versions prior to the macOS updates that carry the fixed WebKit (Ventura, Monterey, and Big Sur branches) |
| Apple WebKit (affects multiple products, including non-Apple HTML parsers that use WebKit) | All builds prior to the May 2023 WebKit fixes |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- safari, ipados, iphone os, macos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H