MEDIUM

CVE-2023-42916

Apple Safari 2023-11-30 CVSS v3.1
CVSS
6.5
KEV

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Summary dbcve.org

An out-of-bounds read vulnerability in WebKit (Safari's rendering engine) allows processing of malicious web content to read sensitive memory beyond intended boundaries, potentially exposing private data. The issue was addressed through improved input validation in the affected Apple products.

Mitigation

Apply the available security updates (iOS 17.1.2/iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2) to all affected devices. For systems running iOS versions before 16.7.1, investigate potential prior compromise as active exploitation was reported.

Weakness (CWE)

CWE-125 Out-of-bounds Read

EPSS Score

17.82%
Probability of exploitation in next 30 days
97.1th percentile

References

http://seclists.org/fulldisclosure/2023/Dec/12 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/13 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/3 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/4 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/5 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/8 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Jan/35 Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2023/12/05/1 Mailing List, Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AD2KIHHCUBQC2YYH3FJWAHI5BG3QETOH/ Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P5LQS6VEI7VIZNC7QGQ62EOV45R5RJIR/ Mailing List https://security.gentoo.org/glsa/202401-04 Third Party Advisory https://support.apple.com/en-us/HT214031 Vendor Advisory https://support.apple.com/en-us/HT214032 Vendor Advisory https://support.apple.com/en-us/HT214033 Vendor Advisory https://support.apple.com/kb/HT214033 Vendor Advisory https://support.apple.com/kb/HT214034 Vendor Advisory https://support.apple.com/kb/HT214062 Vendor Advisory https://www.debian.org/security/2023/dsa-5575 Mailing List https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-42916 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE