CVE-2023-42916
KEVmassWebKit Out-of-Bounds Read in Apple iOS, macOS, Safari Leaks Sensitive Data
CISA: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
An out-of-bounds read (CWE-125) in Apple's WebKit browser engine, tracked as CVE-2023-42916, can leak sensitive information when WebKit processes maliciously crafted web content; Apple addressed it with improved input validation. An attacker would trigger the flaw by getting a user to load attacker-controlled web content in Safari or another WebKit-based browser or web view, gaining access to memory contents (high confidentiality impact, no integrity or availability impact per the CVSS vector). Affected software includes iOS and iPadOS prior to 17.1.2, macOS Sonoma prior to 14.1.2, and Safari prior to 17.1.2, with the advisory also covering WebKitGTK as shipped in Fedora and Debian. Apple reported that this issue may have been exploited against versions of iOS before iOS 16.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-12-04, indicating confirmed in-the-wild exploitation; there is no known public proof-of-concept, and EPSS estimates a 17.8% probability of exploitation in the next 30 days (97th percentile). The batch of Apple patches around this release (iOS, macOS, and Safari updates for actively exploited WebKit flaws) suggests patching urgency is high for all Apple-device fleets.
What to do: Upgrade to iOS/iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2 (or later); organizations still running older iOS lines should also move devices off versions before iOS 16.7.1, which Apple cited in its exploitation report. This flaw is on the CISA KEV list (added 2023-12-04), so US federal agencies must apply the vendor remediation or discontinue use by the KEV due date. Fedora and Debian administrators should apply the latest distribution security updates for WebKitGTK and confirm no outdated WebKitGTK-based packages remain.
| apple iPhone OS (iOS) | Versions prior to iOS 17.1.2 (fixed in iOS 17.1.2); Apple notes exploitation may have occurred against versions of iOS before 16.7.1 |
| apple iPadOS | Versions prior to iPadOS 17.1.2 (fixed in iPadOS 17.1.2) |
| apple macOS (Sonoma) | macOS Sonoma versions prior to 14.1.2 (fixed in macOS Sonoma 14.1.2) |
| apple Safari | Versions prior to Safari 17.1.2 (fixed in Safari 17.1.2) |
| WebKitGTK | — |
| fedoraproject Fedora Linux | — |
| Debian Linux | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
- Affected
- Apple Multiple Products
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- applefedoraprojectdebianwebkitgtk
- Products
- safari, ipados, iphone os, macos, fedora, debian linux, webkitgtk\+
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N