June 2023 Patch Tuesday forecast: Don't forget about Apple
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-32373 | WebKit Use-After-Free Zero-Day in Apple iOS, Safari, macOS Enables Code Execution CVE-2023-32373 is a use-after-free memory-corruption flaw (CWE-416) in WebKit, the web-content engine used across Apple's platforms. It is triggered when an affected device processes maliciously crafted web content, such as a hostile webpage or embedded web view, and requires user interaction. A successful attacker gains arbitrary code execution on the victim device, with high impact to confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). All products shipping vulnerable WebKit are exposed, including iPhone, iPad, Mac (Ventura), Apple Watch, Apple TV, and Safari, plus WebKitGTK-based packages such as those in Red Hat Enterprise Linux. Apple reports the flaw may have been actively exploited; CISA added it to the Known Exploited Vulnerabilities catalog on 2023-05-22, and fixes shipped in iOS/iPadOS 16.5 and 15.7.6, macOS Ventura 13.4, Safari 16.5, watchOS 9.5, and tvOS 16.5. Do: Upgrade to the fixed releases: iOS/iPadOS 16.5 (or 15.7.6 on older devices), macOS Ventura 13.4, Safari 16.5, watchOS 9.5, and tvOS 16.5, and apply Red Hat's updated WebKitGTK packages on affected Linux systems. Because the flaw is in CISA's KEV catalog and reported as actively exploited, federal agencies and prioritized defenders should patch by the KEV deadline. Users who cannot update immediately should avoid browsing untrusted web content, and admins should verify installed OS and Safari versions against the fixed releases. | 8.8 group max | 12% | KEV |
| mass≈1 billion+ Apple devices and Safari installations (essentially the entire unpatched Apple installed base) | |
| CVE-2023-3079 | Type Confusion in Google Chromium V8 Engine Exploited in the Wild CVE-2023-3079 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine that powers Google Chromium, triggerable remotely when a user visits or is directed to a specially crafted HTML page. Successful exploitation causes heap corruption, which a remote attacker can leverage to execute code within the affected browser's renderer process. Every browser or application built on the Chromium engine is potentially affected, explicitly including Google Chrome, Microsoft Edge, and Opera. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-06-07 with a required action to apply vendor updates, and EPSS assigns a 32.1% probability of exploitation activity in the next 30 days (98th percentile). No public proof-of-concept code is known, but the KEV listing confirms real-world attacks, making rapid patching of all Chromium-based browsers a priority. Do: Immediately update Google Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers (including Chromium-embedded applications) to the latest vendor release, per the CISA KEV required action to apply updates per vendor instructions; confirm the update applied via the browser's About/Settings page. As a stopgap where patching is delayed, restrict browsing to trusted sites or disable JavaScript where feasible, since exploitation requires the renderer to process a crafted HTML page. | 8.8 | 32% | KEV PoC |
| mass3+ billion users (Chrome's global install base alone; Chromium-based Edge and Opera add hundreds of millions more) |
Full article677 words · extracted from helpnetsecurity.com · click to collapse
UPDATE: June 13, 11:35 AM PT – June 2023 Patch Tuesday was released.

The odd month-to-month pattern of CVEs addressed by Microsoft continued with the May Patch Tuesday. After seeing high numbers for April, we saw 20 and 23 CVEs fixed for Windows 11 and 10, respectively, in May. And after 62 CVEs were fixed for Server 2012 in April, there were only 16 in May. What will we see this month? Time will tell, but before we talk about the forecast for Microsoft, let’s take a quick look at some Apple activity.

Spotlight on Apple
Apple was in the spotlight this past month with both positive and not so positive headlines. On the positive side, Apple hosted its annual Worldwide Developers Conference this week with announcements around the new Vision Pro ‘spatial computer’ powered by the new visionOS, iOS 17 updates, the upcoming Sonoma OS release, new M2 hardware, and much more.
On the negative side, in mid-May Apple released zero-day updates to address three critical vulnerabilities. These three vulnerabilities were found in the WebKit browser engine and are CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373. Fixes for these vulnerabilities were provided in Big Sur 11.7.7, Monterey 12.6.6, Ventura 13.4, iOS 16.5, and iPadOS 16.5. Two of these vulnerabilities were addressed as part of the Rapid Security Responses program Apple introduced last month. They are known to be exploited, so ensure you include these updates in your monthly process if you have Apple equipment.
Apple is not alone in the zero-day release category – Google also released update 114.0.5735.110 for Windows and 114.0.5735.106 for macOS and Linux to address CVE-2023-3079. This CVE, ‘Type Confusion in V8’, is known to exist in the wild per Google.
DBIR 2023
The Verizon Data Breach Investigations Report (DBIR 2023) was released June 6, and full-disclosure Ivanti was a contributing partner to the report. As expected, most attacks are from an external source (83%) and 74% involve a human element due to “error, privilege misuse, use of stolen credentials or social engineering.”
Nearly 24% of the attacks involved ransomware, which is about the same as last year, but most importantly 95% of the attacks were financially driven. Log4j was reported as the most exploited vulnerability. This report is a great resource providing year-over-year comparisons of data breach activity and an excellent summary of current trends.
Windows 10 21H2 Home and Professional
Windows 10 21H2 Home and Professional will reach EOS this month, so plan accordingly. I discussed some mitigation options in last month’s blog if needed to stay on this version beyond the EOS date. Also, it’s now only six months until Server 2012/Server 2012 R2 reach general EOS. Microsoft will be offering their Extended Security Updates (ESU) for another three years, but if the ESU is needed, you’ll want to plan ahead to make that transition smoothly when the time comes.
June 2023 Patch Tuesday forecast
- After a major lull in CVEs addressed last month, expect Microsoft to be back on track with their annual averages for both this operating systems and Office application updates next week. The preview update included some printer fixes, so we may be finally back to some stability with printer management and functionality.
- Adobe Acrobat and Reader received their last update in April. There are no pre-announcements at this time, but I would watch for a minor update next week because we are due.
- Apple provided a major set of updates on May 18th. Please deploy them as soon as possible due to the known zero-day vulnerabilities. I don’t anticipate any new updates next week due to the developer conference and recent releases.
- Google released several dev and beta updates this week which could result in official releases next week.
- Mozilla released Firefox 114 and Firefox ESR 192.12 this week, so we may only see a Thunderbird update next week.
There were several third-party, emergency zero-day releases ahead of this Patch Tuesday, so we may only see the usual Microsoft fare next week. This could mean a standard deployment next week – unless you forgot about Apple!
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/06/09/june-2023-patch-tuesday-forecast/