PT-2023-1841 · Apple+8 · Ios+12
Published
2023-02-13
·
Updated
2024-06-28
·
CVE-2023-23529
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apple Multiple Products versions prior to iOS 15.7.4
Apple Multiple Products versions prior to iPadOS 15.7.4
Apple Multiple Products versions prior to iOS 16.3.1
Apple Multiple Products versions prior to iPadOS 16.3.1
Apple Multiple Products versions prior to macOS Ventura 13.2.1
Apple Multiple Products versions prior to Safari 16.3
Description
A type confusion issue was addressed with improved checks. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. The issue is related to the WebKit framework of the browser, which could allow arbitrary code execution after an unsuspecting user visits a compromised URL.
Recommendations
For versions prior to iOS 15.7.4, update to iOS 15.7.4 or later.
For versions prior to iPadOS 15.7.4, update to iPadOS 15.7.4 or later.
For versions prior to iOS 16.3.1, update to iOS 16.3.1 or later.
For versions prior to iPadOS 16.3.1, update to iPadOS 16.3.1 or later.
For versions prior to macOS Ventura 13.2.1, update to macOS Ventura 13.2.1 or later.
For versions prior to Safari 16.3, update to Safari 16.3 or later.
Fix
Buffer Overflow
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Suse
Ubuntu
Ios
Ipados
Macos Ventura