Junglewise Threat Intelligence

CVE-2023-37450: Apple Multiple Products WebKit Code Execution Vulnerability

CVE-2023-37450 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-07-13

Technologies: Apple Safari, WebKitGTK, Apple watchOS, Apple iPadOS, Apple Multiple Products, Apple macOS Ventura, Apple Tvos. Vendors: Apple, Webkitgtk.

Executive brief

An unspecified vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks and affects multiple Apple operating systems and browsers, as well as third-party products utilizing WebKit.

Affected products

  • Apple WebKit
  • Apple iOS before 16.6
  • Apple iPadOS before 16.6
  • Apple macOS Ventura before 13.5
  • Apple Safari before 16.5.2
  • Apple tvOS before 16.6
  • Apple watchOS before 9.6
  • WebKitGTK WebKitGTK+ before 2.42.3

Timeline

  • 2023-07-13: disclosed: Initial publication date and addition to CISA KEV catalog
  • 2023-07-13: patched: Fixes released in iOS 16.6, macOS 13.5, and other Apple OS updates
  • 2023-07-13: kev added
  • 2023-07-13: exploited: Apple reported awareness of active exploitation at the time of disclosure

Related threats