Executive brief
A use-after-free vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue stems from improper memory management and affects multiple Apple operating systems and browsers, as well as third-party products utilizing WebKit.
Affected products
- Apple WebKit
- Apple Safari < 16.5
- Apple iOS < 15.7.6, 16.0 < 16.5
- Apple iPadOS < 15.7.6, 16.0 < 16.5
- Apple macOS Ventura < 13.4
- Apple tvOS < 16.5
- Apple watchOS < 9.5
- WebKitGTK WebKitGTK+ < 2.42.3
Timeline
- 2023-05-22: disclosed
- 2023-05-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-05-22: patched: Fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6/16.5, iPadOS 15.7.6/16.5, and Safari 16.5.
- 2023-05-22: exploited: Apple is aware of reports that this issue may have been actively exploited.