EXPOSURES › CVE-2023-32373
CVE-2023-32373
HIGH ⌖ ON CISA KEV · EXPLOITEDApple WebKit Use-After-Free Vulnerability enables code execution.
Apple's WebKit in iOS, iPadOS, macOS, tvOS, watchOS, and Safari contains a use-after-free vulnerability that can lead to code execution when processing malicious web content. This poses a significant risk to HTML parsers using WebKit, including non-Apple products. DIB organizations should ensure their systems are updated to mitigate this vulnerability.
Shame score — This vulnerability is actively exploited and could lead to code execution, impacting a wide range of Apple products and potentially non-Apple systems.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.