EXPOSURES › CVE-2023-32439
CVE-2023-32439
HIGH ⌖ ON CISA KEV · EXPLOITEDWebKit Type Confusion Vulnerability in Apple products allows remote code execution.
Apple's WebKit in iOS, iPadOS, macOS, and Safari contains a type confusion vulnerability that can lead to remote code execution when processing malicious web content. This poses a significant risk to systems that rely on WebKit for HTML parsing, including non-Apple products. Organizations should ensure their systems are updated to mitigate this vulnerability.
Shame score — This vulnerability is actively exploited and could lead to remote code execution, impacting a wide range of systems and applications.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.