PT-2023-4260 · Apple+9 · Webkit+14

Boris Larin

+6

·

Published

2023-03-27

·

Updated

2025-12-08

·

CVE-2023-32435

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WebKitGTK versions prior to 2.40.4-0ubuntu0.22.04.1 Safari versions prior to 16.4 iOS versions prior to 16.4 and iPadOS versions prior to 16.4 iOS versions prior to 15.7.7 and iPadOS versions prior to 15.7.7 macOS Ventura versions prior to 13.3
Description This vulnerability is a memory corruption issue within WebKit, potentially allowing arbitrary code execution. The issue stems from improved state management and has been reported as actively exploited in the wild against iOS versions released before iOS 15.7. The vulnerability affects multiple Apple products, including Safari, iOS, and iPadOS, as well as WebKitGTK. The root cause involves a memory corruption issue within WASM due to allowing moving of not fitting offsets into instruction.
Recommendations Update WebKitGTK to version 2.40.4-0ubuntu0.22.04.1 or later. Update Safari to version 16.4 or later. Update iOS to version 16.4 or later. Update iPadOS to version 16.4 or later. Update macOS Ventura to version 13.3 or later. Update iOS to version 15.7.7 or later. Update iPadOS to version 15.7.7 or later.

Exploit

Fix

RCE

Buffer Overflow

Memory Corruption

Code Injection

Weakness Enumeration

Related Identifiers

ALSA-2023:4201
ALSA-2023:4202
ALSA-2023_4201
ALSA-2023_4202
BDU:2023-04575
CESA-2023_4202
CVE-2023-32435
DSA-5396-1
DSA-5396-2
ELSA-2023-4201
ELSA-2023-4202
MGASA-2023-0229
OPENSUSE-SU-2023_3233-1
OPENSUSE-SU-2023_3419-1
RHSA-2023:4201
RHSA-2023:4202
RHSA-2023_4201
RHSA-2023_4202
RHSA-2025:10364
RLSA-2023:4201
RLSA-2023:4202
RLSA-2023_4201
RLSA-2023_4202
SUSE-SU-2023:3233-1
SUSE-SU-2023:3237-1
SUSE-SU-2023:3300-1
SUSE-SU-2023:3419-1
SUSE-SU-2023_3233-1
SUSE-SU-2023_3237-1
SUSE-SU-2023_3419-1
USN-6264-1

Affected Products

Almalinux
Astra Linux
Centos
Debian
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Safari
Suse
Ubuntu
Webkit
Ios
Ipados
Macos Ventura