Skip to content
COOEY

EXPOSURES › CVE-2023-23529

CVE-2023-23529

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-02-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-23529 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Apple's Safari and iPadOS WebKit vulnerable to code execution via malicious web content

Apple's Safari and iPadOS WebKit, used across multiple Apple products, have a type confusion vulnerability that has been actively exploited, potentially leading to code execution. This impacts a wide range of products and could allow attackers to compromise systems.

Shame score — Actively exploited vulnerability with high potential for widespread impact.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.