Junglewise Threat Intelligence

CVE-2023-32373: Apple Multiple Products WebKit Use-After-Free Vulnerability

CVE-2023-32373 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-05-22

Technologies: Apple iPadOS, Apple watchOS, Apple macOS Ventura, Apple Tvos, Apple Safari, Apple Multiple Products, WebKitGTK. Vendors: Apple, Webkitgtk.

Executive brief

A use-after-free vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue stems from improper memory management and affects multiple Apple operating systems and browsers, as well as third-party products utilizing WebKit.

Affected products

  • Apple WebKit
  • Apple Safari < 16.5
  • Apple iOS < 15.7.6, 16.0 < 16.5
  • Apple iPadOS < 15.7.6, 16.0 < 16.5
  • Apple macOS Ventura < 13.4
  • Apple tvOS < 16.5
  • Apple watchOS < 9.5
  • WebKitGTK WebKitGTK+ < 2.42.3

Timeline

  • 2023-05-22: disclosed
  • 2023-05-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-22: patched: Fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6/16.5, iPadOS 15.7.6/16.5, and Safari 16.5.
  • 2023-05-22: exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats