Junglewise Threat Intelligence

CVE-2023-41993: Apple Multiple Products WebKit Code Execution Vulnerability

CVE-2023-41993 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-09-25

Technologies: Apple macOS Sonoma, WebKitGTK Project WebKitGTK, Apple iPadOS, Apple Safari, Apple Multiple Products. Vendors: Apple.

Executive brief

A code execution vulnerability exists in Apple WebKit due to improper checks when processing web content. An attacker can achieve arbitrary code execution by enticing a user to process maliciously crafted web content. This issue was reportedly exploited in the wild against iOS versions prior to 16.7.

Affected products

  • Apple WebKit
  • Apple Safari before 17.0
  • Apple iOS before 17.0.1
  • Apple iPadOS before 17.0.1
  • Apple macOS Sonoma before 14.0
  • WebKitGTK Project WebKitGTK before 2.42.2

Timeline

  • 2023-09-25: disclosed
  • 2023-09-25: kev added: Added to CISA KEV catalog
  • 2023-09-25: patched: Fixed in macOS Sonoma 14, iOS 17.0.1, iPadOS 17.0.1, and Safari 17.0
  • 2023-09-25: exploited: Apple is aware of reports of active exploitation against iOS versions before 16.7.

Related threats