Skip to content
COOEY

EXPOSURES › CVE-2023-32409

CVE-2023-32409

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-05-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-32409 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

WebKit sandbox escape vulnerability in Apple products allows remote code execution.

A critical vulnerability in Apple's WebKit sandbox allows remote attackers to execute arbitrary code, impacting multiple Apple products and potentially non-Apple products using WebKit. This is a high-risk issue that could lead to data breaches or other malicious activities. DIB organizations should ensure their systems are updated and monitor for any signs of exploitation.

Shame score — This vulnerability is critical and has been actively exploited, leading to significant security risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.