ZeroHour

CVE-2023-43000

KEV PoC mass1

Use-After-Free in Apple WebKit: Safari, iOS, iPadOS, macOS (CVE-2023-43000)

CISA: Apple Multiple products Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2023-43000 is a use-after-free vulnerability (CWE-416) in Apple's web content processing (WebKit) that was addressed with improved memory management. It is triggered when a device processes maliciously crafted web content, which per the CVSS vector requires user interaction such as visiting an attacker-controlled page. Successful exploitation causes memory corruption, and the high confidentiality, integrity, and availability scores indicate an attacker can likely gain code execution or data compromise on the target device. Any unpatched user of Safari, iOS, iPadOS, or macOS macOS versions earlier than the fixed releases is affected, including older iOS devices that Apple has now issued emergency updates for. The flaw is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-03-05, a public PoC reference ties it to the Coruna iOS exploit kit (a spy-grade kit with 23 exploits used for financial crime), and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile).

What to do: Update affected systems to macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, or, for older devices still on iOS 15, iOS/iPadOS 15.8.7. Federal agencies under BOD 22-01 must apply vendor mitigations by the KEV deadline or discontinue use of affected products. Because exploitation requires user interaction with crafted web content, prioritize patching internet-facing and at-risk mobile fleets, and warn users to avoid untrusted links as an interim measure.

Affected
Apple SafariVersions prior to Safari 16.6 (fixed in Safari 16.6)
Apple iPhone OS (iOS)Versions prior to iOS 16.6 (fixed in iOS 16.6); older devices on iOS versions prior to iOS 15.8.7 (fixed in iOS 15.8.7)
Apple iPadOSVersions prior to iPadOS 16.6 (fixed in iPadOS 16.6); older devices on iPadOS versions prior to iPadOS 15.8.7 (fixed in iPadOS 15.8.7)
Apple macOSmacOS Ventura versions prior to 13.5 (fixed in macOS Ventura 13.5)
Estimated exposure
mass≈1 billion+ devices and users (Apple's active iPhone/iPad/Mac install base plus Safari users worldwide) — Apple's active iPhone and iPad install base exceeds a billion devices and Safari ranks among the world's largest browsers with roughly a billion users, so any unpatched subset of these populations is plausibly in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
safari, ipados, iphone os, macos
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news