Executive brief
A memory corruption vulnerability in WebKit allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved locking and has been actively exploited in the wild against versions of iOS prior to 16.7.1.
Affected products
- Apple iOS before 17.1.2
- Apple iPadOS before 17.1.2
- Apple macOS Sonoma before 14.1.2
- Apple Safari before 17.1.2
- Apple WebKit
Timeline
- 2023-12-04: disclosed
- 2023-12-04: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-11-30: patched: Fixed in iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2
- 2023-12-04: exploited: Apple reported awareness of exploitation in the wild.