Junglewise Threat Intelligence

CVE-2023-28205: Apple Multiple Products WebKit Use-After-Free Vulnerability

CVE-2023-28205 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-04-10

Technologies: Apple macOS Ventura, Apple iPadOS, Apple Multiple Products, Apple Safari. Vendors: Apple.

Executive brief

A use-after-free vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed through improved memory management across multiple Apple operating systems and the Safari browser.

Affected products

  • Apple WebKit
  • Apple Safari Before 16.4.1
  • Apple iOS Before 15.7.5, Before 16.4.1
  • Apple iPadOS Before 15.7.5, Before 16.4.1
  • Apple macOS Ventura Before 13.3.1

Timeline

  • 2023-04-10: disclosed
  • 2023-04-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-10: patched: Fixed in Safari 16.4.1, iOS 15.7.5/16.4.1, iPadOS 15.7.5/16.4.1, and macOS Ventura 13.3.1
  • 2023-04-10: exploited: Apple reported awareness of active exploitation at the time of disclosure.

Related threats