Apple backports fix for exploited WebKit bug to older iPhones, iPads (CVE-2023-23529)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-23529 | WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known. Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched. | 8.8 | 10% | KEV |
| massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran… | |
| CVE-2023-23537 | A privacy issue was addressed with improved private data redaction for log entries. A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, watchOS 9.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2023-27965 +1 in the same advisory: …27951 | A memory corruption issue was addressed with improved state management. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Studio Display Firmware Update 16.4. An app may be able to execute arbitrary code with kernel privileges. NVD description · AI analysis pending | 7.8 group max | <1% |
| — |
Full article371 words · extracted from helpnetsecurity.com · click to collapse
Apple has released security updates for – pardon the pop-culture reference – everyhing everywhere all at once, and has fixed the WebKit vulnerability (CVE-2023-23529) exploited in the wild for users of older iPhones and iPads.

This latest batch of security updates targets the iOS and iPad 16.x and 15.x branches; macOS Big Sur, Monterey and Ventura; watchOS and tvOS; Safari; and Studio Display, a standalone computer monitor / external display.
The CVE-2023-23529 fix for older iPhones
The presently most important fix among those delivered is the one for CVE-2023-23529, a type confusion issue in the WebKit browser engine, which can be triggered by maliciously crafted web content and ultimately allow code execution.
Reported by an anonymous researcher, the flaw “may have been actively exploited” (according to Apple) and has initially been fixed in iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, and Safari 16.3.1 in February 2022.
Details about specific attacks exploiting this flaw have yet to be publicly shared, but users of iPhone 6s, 7, SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) devices are advised to implement the update as soon as possible.
Other vulnerabilities of note
Additional WebKit flaws have been fixed in Safari and macOS Ventura updates. Among the most attention-grabbing (though not critical) vulnerabilities fixed this Monday are:
- CVE-2023-27951, Gatekeeper bypass flaw that can be triggered with an archive file
- CVE-2023-23537, a privacy issue in the Find My component that could be exploited by an app to read sensitive location information
- CVE-2023-27965, a memory corruption issue that could allow an app to execute arbitrary code with kernel privileges
CVE-2023-27965 was fixed in macOS Ventura and Studio Display’s firmware update.
“Apparently, if you’re running macOS Ventura and you’ve hooked your Mac up to a Studio Display, just updating the Ventura operating system itself isn’t enough to secure you against potential system-level attacks,” noted Paul Ducklin, Sophos Head of Technology for the Asia Pacific region.
He also delineated a security-minded Studio Display update process for those users who won’t be able to implement the update immediately or for a while (i.e., before a PoC is publicly released or criminals figure out how to exploit the flaw).
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/03/28/cve-2023-23529-older-iphones-ipads/