Junglewise Threat Intelligence

CVE-2023-42916: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability

CVE-2023-42916 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2023-12-04

Technologies: Apple Safari, Apple macOS Sonoma, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

An out-of-bounds read vulnerability in the WebKit engine allows for the disclosure of sensitive information when processing maliciously crafted web content. The issue was addressed through improved input validation in multiple Apple operating systems and the Safari browser.

Affected products

  • Apple WebKit Versions before iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2
  • Apple iOS before 17.1.2
  • Apple iPadOS before 17.1.2
  • Apple macOS Sonoma before 14.1.2
  • Apple Safari before 17.1.2

Timeline

  • 2023-11-30: patched: Apple released updates for iOS, iPadOS, macOS, and Safari.
  • 2023-12-04: disclosed: CVE-2023-42916 published.
  • 2023-12-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-12-04: exploited: Apple reported awareness of exploitation against versions of iOS before 16.7.1.

Related threats