Junglewise Threat Intelligence

CVE-2023-32439: Apple Multiple Products WebKit Type Confusion Vulnerability

CVE-2023-32439 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-06-23

Technologies: Apple Multiple Products, WebKitGTK. Vendors: Apple, Webkitgtk.

Executive brief

A type confusion vulnerability in the WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks across multiple Apple operating systems and the Safari browser.

Affected products

  • Apple WebKit Fixed in iOS 16.5.1, iPadOS 16.5.1, iOS 15.7.7, iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1
  • WebKitGTK WebKitGTK+ up to (excluding) 2.42.3

Timeline

  • 2023-06-23: disclosed: Apple is aware of reports that this issue may have been actively exploited.
  • 2023-06-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-06-23: patched: Fixed in iOS 16.5.1, iPadOS 16.5.1, iOS 15.7.7, iPadOS 15.7.7, macOS Ventura 13.4.1, and Safari 16.5.1.

Related threats