Skip to content
COOEY

EXPOSURES › CVE-2023-28205

CVE-2023-28205

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-04-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-28205 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Apple's Safari and macOS WebKit vulnerable to code execution via malicious web content.

Apple's Safari and macOS WebKit contain a use-after-free vulnerability that could lead to code execution when processing maliciously crafted web content, impacting Apple's Safari browser and third-party products using WebKit. This vulnerability is actively exploited in the wild.

Shame score — Actively exploited in the wild with no patch available at the time of reporting.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.