EXPOSURES › CVE-2023-32409
CVE-2023-32409
HIGH ⌖ ON CISA KEV · EXPLOITEDWebKit sandbox escape vulnerability in Apple products allows remote code execution.
A critical vulnerability in Apple's WebKit sandbox allows remote attackers to execute arbitrary code, impacting multiple Apple products and potentially non-Apple products using WebKit. This is a high-risk issue that could lead to data breaches or other malicious activities. DIB organizations should ensure their systems are updated and monitor for any signs of exploitation.
Shame score — This vulnerability is critical and has been actively exploited, leading to significant security risks.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.