Executive brief
A code execution vulnerability exists in Apple WebKit due to improper checks when processing web content. An attacker can achieve arbitrary code execution by enticing a user to process maliciously crafted web content. This issue was reportedly exploited in the wild against iOS versions prior to 16.7.
Affected products
- Apple WebKit
- Apple Safari before 17.0
- Apple iOS before 17.0.1
- Apple iPadOS before 17.0.1
- Apple macOS Sonoma before 14.0
- WebKitGTK Project WebKitGTK before 2.42.2
Timeline
- 2023-09-25: disclosed
- 2023-09-25: kev added: Added to CISA KEV catalog
- 2023-09-25: patched: Fixed in macOS Sonoma 14, iOS 17.0.1, iPadOS 17.0.1, and Safari 17.0
- 2023-09-25: exploited: Apple is aware of reports of active exploitation against iOS versions before 16.7.