Junglewise Threat Intelligence

CVE-2023-32409: Apple Multiple Products WebKit Sandbox Escape Vulnerability

CVE-2023-32409 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2023-05-22

Technologies: Apple macOS Ventura, Apple Tvos, Apple Safari, Apple Multiple Products, Apple watchOS. Vendors: Apple.

Executive brief

A sandbox escape vulnerability in Apple's WebKit engine allows a remote attacker to break out of the Web Content sandbox. The issue, caused by insufficient bounds checks, has been reported as being actively exploited in the wild.

Affected products

  • Apple WebKit
  • Apple Safari before 16.5
  • Apple iOS and iPadOS before 15.7.8, before 16.5
  • Apple macOS Ventura before 13.4
  • Apple tvOS before 16.5
  • Apple watchOS before 9.5

Timeline

  • 2023-05-22: disclosed
  • 2023-05-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-22: patched: Fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8, iPadOS 15.7.8, Safari 16.5, iOS 16.5, and iPadOS 16.5.
  • 2023-05-22: exploited: Apple is aware of reports of active exploitation.

Related threats