HIGH

CVE-2023-42917

Apple Safari 2023-11-30 CVSS v3.1
CVSS
8.8
KEV

Description

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Summary dbcve.org

A memory corruption vulnerability in WebKit (Safari's browser engine) that was addressed with improved locking. Processing malicious web content could lead to arbitrary code execution. This was a zero-day vulnerability actively exploited in the wild targeting iOS versions before iOS 16.7.1.

Mitigation

Update to iOS 17.1.2/iPadOS 17.1.2 or later, macOS Sonoma 14.1.2, or Safari 17.1.2. For legacy systems, iOS 16.7.1 also contains the fix.

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

9.3%
Probability of exploitation in next 30 days
95.2th percentile

References

http://seclists.org/fulldisclosure/2023/Dec/12 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/13 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/3 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/4 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/5 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2023/Dec/8 Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Jan/35 Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2023/12/05/1 Mailing List, Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AD2KIHHCUBQC2YYH3FJWAHI5BG3QETOH/ Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P5LQS6VEI7VIZNC7QGQ62EOV45R5RJIR/ Mailing List https://security.gentoo.org/glsa/202401-04 Third Party Advisory https://support.apple.com/en-us/HT214031 Vendor Advisory https://support.apple.com/en-us/HT214032 Vendor Advisory https://support.apple.com/en-us/HT214033 Vendor Advisory https://support.apple.com/kb/HT214033 Vendor Advisory https://support.apple.com/kb/HT214034 Vendor Advisory https://support.apple.com/kb/HT214062 Vendor Advisory https://www.debian.org/security/2023/dsa-5575 Mailing List, Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-42917 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE