Apple emergency patch to fix zero-day prevents some websites from displaying properly
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-37450 | Arbitrary Code Execution in Apple WebKit (iOS, iPadOS, macOS, Safari, tvOS, watchOS) CVE-2023-37450 is a high-severity (CVSS 8.8) arbitrary code execution vulnerability in Apple's WebKit browser engine, affecting iOS, iPadOS, Safari, macOS Ventura, tvOS, watchOS, and WebKitGTK. It is triggered when an affected device processes maliciously crafted web content — for example, when a user is lured into visiting an attacker-controlled webpage (user interaction is required, hence the UI:R CVSS vector). Successful exploitation grants the attacker arbitrary code execution within the web-content/browser context, the typical entry point for full iPhone, iPad, or Mac compromise chains. Anyone running iPhone OS/iPadOS earlier than 16.6, Safari earlier than 16.5.2, macOS Ventura earlier than 13.5, tvOS earlier than 16.6, watchOS earlier than 9.6, or unpatched WebKitGTK builds is affected. Apple reports the issue may have been actively exploited before it was patched, CISA added it to the KEV catalog on 2023-07-13, and EPSS assigns an 18.9% probability (97th percentile) of exploitation over the next 30 days. Do: Upgrade immediately to iOS 16.6 / iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6, and watchOS 9.6, or apply the latest available patch for older OS branches on devices that cannot take the 16.x/Ventura updates; this is a CISA KEV entry with a federal remediation requirement. Because exploitation occurs through normal web browsing, patching is the only reliable mitigation — avoid untrusted websites as an interim measure. WebKitGTK users should update to the latest patched WebKitGTK release and verify that dependent applications have been rebuilt against the fixed library. | 8.8 | 19% | KEV |
| mass≈2 billion active Apple devices (WebKit is the web engine for iOS/iPadOS, Safari, tvOS and watchOS); no public counts of exploited devices are known |
Full article447 words · extracted from therecord.media · click to collapse
Apple said it is planning to release a new version of a patch it issued Monday following reports that the fix is causing secondary issues for users. Apple published a Rapid Security Responses (RSR) advisory Monday addressing CVE-2023-37450, a vulnerability they say “may have been actively exploited.” The zero-day vulnerability affects WebKit, a browser engine used by many macOS and iOS applications. On Tuesday, the company said it is “aware of an issue where this Rapid Security Response might prevent some websites from displaying properly,” adding that new versions “will be available soon to address this issue.” Apple provided instructions to users who wished to remove the RSR patch from their devices. Several people in the comment section of a MacRumors article on the patch reported having issues opening Facebook and other platforms like Zoom and Instagram. CVE-2023-37450 affects WebKit, which is “foundational to essentially every product in the Apple ecosystem that can render web content and that ranges from the operating systems to Apple’s products to third-party developer products,” according to Zimperium security architect Georgia Weidman. “The very code re-use that has helped make the internet truly ubiquitous and has allowed Apple to provide such diverse offerings unfortunately comes with the associated cost that bad actors can increasingly use the same exploit across entire ecosystems of products,” Weidman added. BleepingComputer, which first reported the patch, said this is the 10th zero-day vulnerability found within Apple products this year. The RSR program is a new offering from Apple designed to “deliver important security improvements between software updates—for example, improvements to the Safari web browser, the WebKit framework stack, or other critical system libraries.” “They may also be used to mitigate some security issues more quickly, such as issues that might have been exploited or reported to exist ‘in the wild,’” Apple said in a document explaining the program. The advisory on Monday is the second RSR release since the program was started. Viakoo’s John Gallagher lauded Apple for taking action to address the growing number of zero-day exploits through the new program and noted that the advisories give customers a “clear indication that the patch is urgent and different from a standard update for functionality and minor bug fixes.” But he warned that the danger is that RSRs “become too frequent and therefore become ‘background noise’ to users as current updates might be.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/apple-emergency-patch-zero-day-prevents-websites-from-displaying-properly