HIGH

CVE-2023-43000

Apple Safari 2025-11-05 CVSS v3.1
CVSS
8.8
KEV

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

Summary dbcve.org

A use-after-free vulnerability in WebKit allows memory corruption when processing maliciously crafted web content. The vulnerability stems from improper memory management where a pointer is accessed after the referenced memory has been freed, potentially allowing remote code execution or memory corruption. This affects Safari 16.6 and iOS/macOS versions prior to the fixes.

Mitigation

Apply the security updates provided by Apple: macOS Ventura 13.5+, iOS 16.6+/iPadOS 16.6+, iOS 15.8.7+/iPadOS 15.8.7+, and Safari 16.6+. For systems that cannot be immediately updated, restrict or disable Safari/web browsing until patches can be applied.

Proof of Concept

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

3.9%
Probability of exploitation in next 30 days
89.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE