CVE-2023-42916
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Summary dbcve.org
An out-of-bounds read vulnerability in WebKit (Safari's rendering engine) allows processing of malicious web content to read sensitive memory beyond intended boundaries, potentially exposing private data. The issue was addressed through improved input validation in the affected Apple products.
Mitigation
Apply the available security updates (iOS 17.1.2/iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2) to all affected devices. For systems running iOS versions before 16.7.1, investigate potential prior compromise as active exploitation was reported.