Apple Fixes WebKit Vulnerability Enabling Same
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41974 | Use-After-Free Kernel Code Execution Flaw in Apple iOS and iPadOS CVE-2023-41974 is a use-after-free (CWE-416) memory-corruption vulnerability in Apple iOS and iPadOS that was addressed with improved memory management. It is triggered locally when an application on the device exercises the affected code path; the CVSS vector (AV:L/UI:R) indicates the attacker needs code running on the device and user interaction, but no network access or privileges. A successful exploit allows an app to execute arbitrary code with kernel privileges, giving the attacker full control over the affected iPhone or iPad. Anyone running iOS/iPadOS versions prior to iOS 17/iPadOS 17, including legacy 15.x devices prior to 15.8.7, is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, and public references tie it to the spy-grade 'Coruna' iOS exploit kit (23 exploits across five chains) used for financial crime, confirming exploitation in the wild. Do: Update iPhones to iOS 17 and iPads to iPadOS 17, or apply the iOS 15.8.7 / iPadOS 15.8.7 emergency updates on legacy hardware that cannot run 17; inventory your fleet for devices on older builds and prioritize them, since the Coruna exploit kit reportedly targets older iOS versions. Until patched, avoid installing apps from untrusted sources, as exploitation requires running a malicious app. Federal agencies must meet the applicable BOD 22-01 required-action deadline for this KEV entry. | 7.8 | 1% | KEV PoC |
| mass≈1 billion+ devices in scope | |
| CVE-2023-43000 | Use-After-Free in Apple WebKit: Safari, iOS, iPadOS, macOS (CVE-2023-43000) CVE-2023-43000 is a use-after-free vulnerability (CWE-416) in Apple's web content processing (WebKit) that was addressed with improved memory management. It is triggered when a device processes maliciously crafted web content, which per the CVSS vector requires user interaction such as visiting an attacker-controlled page. Successful exploitation causes memory corruption, and the high confidentiality, integrity, and availability scores indicate an attacker can likely gain code execution or data compromise on the target device. Any unpatched user of Safari, iOS, iPadOS, or macOS macOS versions earlier than the fixed releases is affected, including older iOS devices that Apple has now issued emergency updates for. The flaw is being actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2026-03-05, a public PoC reference ties it to the Coruna iOS exploit kit (a spy-grade kit with 23 exploits used for financial crime), and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile). Do: Update affected systems to macOS Ventura 13.5, iOS/iPadOS 16.6, Safari 16.6, or, for older devices still on iOS 15, iOS/iPadOS 15.8.7. Federal agencies under BOD 22-01 must apply vendor mitigations by the KEV deadline or discontinue use of affected products. Because exploitation requires user interaction with crafted web content, prioritize patching internet-facing and at-risk mobile fleets, and warn users to avoid untrusted links as an interim measure. | 8.8 | 4% | KEV PoC |
| mass≈1 billion+ devices and users (Apple's active iPhone/iPad/Mac install base plus Safari users worldwide) | |
| CVE-2023-43010 | The issue was addressed with improved memory handling. The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-23222 | Apple WebKit Type Confusion Enables Arbitrary Code Execution Across iOS, macOS, tvOS CVE-2024-23222 is a type confusion flaw (CWE-843) in Apple's WebKit engine that allows arbitrary code execution when a device processes maliciously crafted web content, for example when a user is lured into loading attacker-controlled web pages in Safari or another WebKit-based view (the CVSS vector confirms user interaction is required). It affects a broad slice of the Apple ecosystem: Safari, iPhone OS/iPadOS on the iOS 15, 16 and 17 branches, macOS Monterey/Ventura/Sonoma, tvOS and visionOS, prior to the January 22, 2024 fixes. A successful attacker gains code execution on the target device with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8). The flaw was fixed in Safari 17.3, iOS/iPadOS 17.3, and backported to iOS/iPadOS 15.8.7 and 16.7.5 for devices that cannot upgrade to iOS 17, plus macOS Monterey 12.7.3, Ventura 13.6.4, Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2024-01-23, one day after the fixes shipped, and is associated with the Coruna exploit kit, which reportedly chains multiple exploits to target iOS devices including older versions. Do: Update all affected devices to Safari 17.3, iOS/iPadOS 17.3 (or the iOS/iPadOS 15.8.7 and 16.7.5 backports for devices that cannot run 17), macOS Monterey 12.7.3, macOS Ventura 13.6.4, macOS Sonoma 14.3, tvOS 17.3 and visionOS 1.0.2. Prioritize endpoints used for web browsing and mobile users, since exploitation only requires a user to process crafted web content. The CISA KEV listing (added 2024-01-23) makes applying these vendor updates mandatory under the KEV required action, so verify fleet versions and confirm no devices remain on pre-patch builds. | 8.8 | 11% | KEV |
| massover 1 billion active Apple devices (effectively Apple's entire unpatched iPhone/iPad/Mac/Apple TV fleet) | |
| CVE-2026-20643 | A cross-origin issue in the Navigation API was addressed with improved input validation. A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Background Security Improvements for iOS, iPadOS, and macOS, Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, visionOS 26.4. Processing maliciously crafted web content may bypass Same Origin Policy. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2026-20700 | Exploited Memory Corruption Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS CVE-2026-20700 is a memory corruption (buffer overflow) issue in multiple Apple operating systems that Apple addressed through improved state management. The flaw requires a local attack vector: an attacker who already has some memory-write capability on the device — typically obtained via a chained exploit such as a browser or sandbox escape — can leverage this bug to execute arbitrary code. Attackers gain code execution with the privileges of the compromised component, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 (High) score. All users of iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch running versions earlier than the 26.3 updates are affected. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-12; related CVEs CVE-2025-14174 and CVE-2025-43529 were issued from the same report. Do: Update all Apple devices to iOS/iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3 or later; the fix also addresses related CVE-2025-14174 and CVE-2025-43529 from the same report. Federal agencies must meet the KEV/BOD 22-01 deadline by patching per vendor instructions or discontinuing affected device use. Given the targeted, exploit-kit-driven attacks (e.g., DarkSword/Coruna tooling reported in the wild), prioritize updates for high-risk users such as executives, journalists, and activists, and verify fleet-wide OS versions rather than assuming patch compliance. | 7.8 | 1% | KEV |
| mass≈1.5–2 billion active Apple devices (Apple's publicly reported active install base), with a large share likely on pre-26.3 versions |
Full article405 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 18, 2026Vulnerability / Zero-Day
Apple on Tuesday released its first round of Background Security Improvements to address a security flaw in WebKit that affects iOS, iPadOS, and macOS.
The vulnerability, tracked as CVE-2026-20643 (CVSS score: N/A), has been described as a cross-origin issue in WebKit's Navigation API that could be exploited to bypass the same-origin policy when processing maliciously crafted web content.
The flaw affects iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2. It has been addressed with improved input validation in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Security researcher Thomas Espach has been credited with discovering and reporting the shortcoming.
Apple notes that Background Security Improvements are meant for delivering lightweight security releases for components such as the Safari browser, WebKit framework stack, and other system libraries through smaller, ongoing security patches rather than issuing them as part of larger software updates.
The feature is supported and enabled for future releases starting with iOS 26.1, iPadOS 26.1, and macOS 26. In cases where compatibility issues are discovered, the improvements may be temporarily removed and then enhanced in a subsequent software update, Apple adds.
Users can control Background Security Improvements via the Privacy and Security menu in the Settings app. To ensure that they are automatically installed, it's advised to keep the "Automatically Install" option on.
It's worth noting that if users opt to have this setting disabled, they will have to wait until the improvements are included in the next software update. Viewed in that light, the feature is analogous to Rapid Security Response, which it introduced in iOS 16 as a way to install minor security updates.
"If a Background Security Improvement has been applied, and you choose to remove it, your device reverts to the baseline software update (for example, iOS 26.3) with no Background Security Improvements applied," Apple noted in a help document.
The development comes little over a month after Apple issued fixes for an actively exploited zero-day impacting iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS (CVE-2026-20700, CVSS score: 7.8) that could result in arbitrary code execution.
Last week, the iPhone maker also expanded patches for four security flaws (CVE-2023-43010, CVE-2023-43000, CVE-2023-41974, and CVE-2024-23222) that were weaponized as part of the Coruna exploit kit.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html