Junglewise Threat Intelligence

CVE-2023-32435: Apple Multiple Products WebKit Memory Corruption Vulnerability

CVE-2023-32435 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-06-23

Technologies: Apple macOS Ventura, Apple Safari, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A memory corruption vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved state management and has been reported as being actively exploited in the wild against older versions of iOS.

Affected products

  • Apple iOS before 15.7.7, before 16.4
  • Apple iPadOS before 15.7.7, before 16.4
  • Apple macOS Ventura before 13.3
  • Apple Safari before 16.4
  • Apple WebKit

Timeline

  • 2023-06-23: disclosed
  • 2023-06-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-06-23: patched: Fixed in macOS Ventura 13.3, Safari 16.4, iOS/iPadOS 16.4, and iOS/iPadOS 15.7.7
  • 2023-06-23: exploited: Apple is aware of reports of active exploitation against versions of iOS released before iOS 15.7.

Related threats