CVE-2023-42917
KEVmassWebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution
CISA: Apple Multiple Products WebKit Memory Corruption Vulnerability
CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).
What to do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.
| apple iphone os (iOS) | versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1 |
| apple ipados | versions prior to iPadOS 17.1.2 |
| apple macos (Sonoma) | versions prior to macOS Sonoma 14.1.2 |
| apple safari | versions prior to Safari 17.1.2 |
| webkitgtk+ | — |
| debian linux | — |
| fedoraproject fedora | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
- Affected
- Apple Multiple Products
- Required action
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- appledebianfedoraprojectwebkitgtk
- Products
- safari, ipados, iphone os, macos, debian linux, fedora, webkitgtk\+
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H