Skip to content
COOEY

EXPOSURES › CVE-2023-42916

CVE-2023-42916

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-12-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-42916 ↗
⌖ EXPLOITED IN THE WILD SHAME 50/100 exploited-in-wild

Apple's WebKit vulnerability (CVE-2023-42916) allows sensitive information disclosure via malicious web content, and is currently being exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.