Executive brief
A type confusion vulnerability in Apple's WebKit engine allows for arbitrary code execution when processing maliciously crafted web content. The issue was addressed with improved checks across multiple Apple operating systems and the Safari browser.
Affected products
- Apple WebKit
- Apple Safari < 17.3
- Apple iOS and iPadOS < 15.8.7, 16.x < 16.7.5, 17.x < 17.3
- Apple macOS Monterey < 12.7.3
- Apple macOS Ventura < 13.6.4
- Apple macOS Sonoma < 14.3
- Apple tvOS < 17.3
- Apple visionOS < 1.0.2
Timeline
- 2024-01-22: patched: Initial fix shipped in iOS 17.3
- 2024-01-23: disclosed
- 2024-01-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-23: exploited: Reported as exploited in the wild at time of publication