Executive brief
Apple and Red Hat products are affected by a memory handling vulnerability when processing web content. An attacker could exploit this by tricking a user into visiting a malicious website, potentially leading to unauthorized access to sensitive data or system instability. This impact spans across mobile devices, desktop computers, and enterprise server environments.
Technical details
A memory corruption vulnerability exists in multiple Apple operating systems and Red Hat Enterprise Linux environments, primarily triggered during the processing of maliciously crafted web content. The root cause is identified as an out-of-bounds write (CWE-787) or a classic buffer overflow (CWE-120) due to improper memory handling. An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted webpage (User Interaction required). Successful exploitation can lead to arbitrary code execution or a denial-of-service condition. The issue has been addressed by Apple in iOS/iPadOS 17.2, macOS Sonoma 14.2, and Safari 17.2, with corresponding patches released by Red Hat for affected Linux distributions.
Affected products
- Apple iOS Before 17.2, 16.7.15, 15.8.7
- Apple iPadOS Before 17.2, 16.7.15, 15.8.7
- Apple macOS Sonoma Before 14.2
- Apple Safari Before 17.2
- Red Hat Enterprise Linux 7, 8, 9
Timeline
- 2023-12-11: patched: Apple released fixes in iOS 17.2 and related updates.
- 2026-03-12: disclosed: NVD publication date.