CVE-2023-43000
KEV PoC mass1Use-After-Free in Apple WebKit: Safari, iOS, iPadOS, macOS (CVE-2023-43000)
CISA: Apple Multiple products Use-After-Free Vulnerability
CVE-2023-43000 is a use-after-free vulnerability (CWE-416) in Apple's web content processing (WebKit) that was addressed with improved memory management. It is triggered when a device processes maliciously crafted web content, which per the CVSS vector requires user interaction such as visiting an attacker-controlled page. Successful exploitation causes memory corruption, and the high confidentiality, integrity, and availability scores indicate an attacker can likely gain code execution or data compromise on the target device. Any unpatched user of Safari, iOS, iPadOS, or macOS macOS versions earlier than the fixed releases is affected, including older iOS devices that Apple has now issued emergency updates for. The flaw is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-03-05, a public PoC reference ties it to the Coruna iOS exploit kit (a spy-grade kit with 23 exploits used for financial crime), and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile).
What to do: Update affected systems to macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, or, for older devices still on iOS 15, iOS/iPadOS 15.8.7. Federal agencies under BOD 22-01 must apply vendor mitigations by the KEV deadline or discontinue use of affected products. Because exploitation requires user interaction with crafted web content, prioritize patching internet-facing and at-risk mobile fleets, and warn users to avoid untrusted links as an interim measure.
| Apple Safari | Versions prior to Safari 16.6 (fixed in Safari 16.6) |
| Apple iPhone OS (iOS) | Versions prior to iOS 16.6 (fixed in iOS 16.6); older devices on iOS versions prior to iOS 15.8.7 (fixed in iOS 15.8.7) |
| Apple iPadOS | Versions prior to iPadOS 16.6 (fixed in iPadOS 16.6); older devices on iPadOS versions prior to iPadOS 15.8.7 (fixed in iPadOS 15.8.7) |
| Apple macOS | macOS Ventura versions prior to 13.5 (fixed in macOS Ventura 13.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- safari, ipados, iphone os, macos
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H