Junglewise Threat Intelligence

CVE-2023-28204: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

CVE-2023-28204 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2023-05-22

Technologies: Apple iPadOS, Apple macOS Ventura, Apple Tvos, WebKitGTK, Apple Safari, Apple Multiple Products, Apple watchOS. Vendors: Apple, Webkitgtk.

Executive brief

An out-of-bounds read vulnerability in Apple's WebKit engine allows for the disclosure of sensitive information when processing maliciously crafted web content. The issue was addressed through improved input validation across multiple Apple operating systems and the Safari browser.

Affected products

  • Apple WebKit versions before Safari 16.5, iOS 16.5, iPadOS 16.5, macOS Ventura 13.4, tvOS 16.5, watchOS 9.5
  • Apple Safari before 16.5
  • Apple iOS before 15.7.6 and 16.5
  • Apple iPadOS before 15.7.6 and 16.5
  • Apple macOS Ventura before 13.4
  • Apple tvOS before 16.5
  • Apple watchOS before 9.5
  • WebKitGTK WebKitGTK+ before 2.42.3

Timeline

  • 2023-05-22: disclosed: Apple is aware of reports that this issue may have been actively exploited.
  • 2023-05-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-05-22: patched: Fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6/16.5, iPadOS 15.7.6/16.5, and Safari 16.5.

Related threats