ZeroHour

CVE-2023-42917

KEVmass

WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution

CISA: Apple Multiple Products WebKit Memory Corruption Vulnerability

CVSS 3.1
8.8 high
EPSS
9%p95
Published
()
KEV added
AI analysis

CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).

What to do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.

Affected
apple iphone os (iOS)versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1
apple ipadosversions prior to iPadOS 17.1.2
apple macos (Sonoma)versions prior to macOS Sonoma 14.1.2
apple safariversions prior to Safari 17.1.2
webkitgtk+
debian linux
fedoraproject fedora
Estimated exposure
masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base) — Apple has reported an active installed base of over 2 billion devices and Safari serves roughly a billion users, so any WebKit flaw on iOS/iPadOS/macOS/Safari plausibly touches more than a billion installations; Linux exposure via…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
appledebianfedoraprojectwebkitgtk
Products
safari, ipados, iphone os, macos, debian linux, fedora, webkitgtk\+
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news