ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Apple fixes actively exploited WebKit zero-day in iOS, macOS (CVE-2023-23529)

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-23529CVE-2023-23514

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23514
A use after free issue was addressed with improved memory management.

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, macOS Big Sur 11.7.5. An app may be able to execute arbitrary code with kernel privileges.

NVD description · AI analysis pending
7.8<1%
  • apple ipados
  • apple iphone os
  • apple macos
CVE-2023-23529
WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari

CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known.

Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched.

8.810% KEV
  • Apple iPhone OS (iOS) iOS versions prior to the fixed releases; fixed in iOS 16.3.1 and in iOS 15.7.4 on the legacy branch
  • Apple iPadOS iPadOS versions prior to the fixed releases; fixed in iPadOS 16.3.1 and in iPadOS 15.7.4 on the legacy branch
  • Apple macOS (Ventura) macOS Ventura versions prior to 13.2.1
  • +1 more
massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran…
Full article321 words · extracted from helpnetsecurity.com · click to collapse

Apple has released security updates that fix a WebKit zero-day vulnerability (CVE-2023-23529) that “may have been actively exploited.”

CVE-2023-23529

The bug has been fixed in iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3.1, and possibly also in tvOS 16.3.2 and watchOS 9.3.1 – though release notes for the updates for those Internet of Things operating systems have been temporarily witheld.

About CVE-2023-23529

CVE-2023-23529 is a type confusion issue in WebKit, the browser engine powering the Safari browser and other web browsers running on iOS and iPadOS.

The vulnerability is triggered by processing maliciously crafted web content, and may allow attackers to execute arbitrary code on a vulnerable device.

An anonymous researcher has been credited with reporting it, but since the update release notes acknowledge The Citizen Lab at The University of Toronto’s Munk School for their assistance, it’s possible that the vulnerability is being exploited to spy on users (the Lab often researches and reports on the use of mobile spyware around the world).

This is just speculation on our part, though, because as usual Apple did not share any details about the attacks.

Owners of iPhones, iPads and iPad minis are advised to check for available updates and upgrade their devices as soon as possible. Users of older devices (e.g., iPhone 7 and older) will have to wait for the patch to be backported to older iOS and iPadOS branches.

Other fixed vulnerabilities

Users running macOS Ventura also get a patch for CVE-2023-23529 with the OS security update, while those who still use macOS Big Sur and macOS Monterey can close the hole by updating Safari to version 16.3.1.

The iOS and iPadOS update also contains a fix for CVE-2023-23514, a use after free issue in the kernel, which could allow a malicious app to execute arbitrary code with kernel privileges.

The macOS update patches it, as well, along with a privacy issue in the Shortcuts component.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/02/14/cve-2023-23529/