EXPOSURES › CVE-2023-41993
CVE-2023-41993
HIGH ⌖ ON CISA KEV · EXPLOITEDApple WebKit vulnerability allows code execution via malicious web content.
Apple's WebKit vulnerability in iOS, iPadOS, macOS, and Safari allows attackers to execute arbitrary code when processing malicious web content. This poses a significant risk to users and organizations relying on these platforms for HTML parsing. Immediate action is required to mitigate this threat.
Shame score — This vulnerability is actively exploited and could lead to remote code execution, impacting a wide range of Apple products and third-party applications.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.