Buffer overflow in macOS - CVE-2023-23496
Published: January 23, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing HTML content in WebKit. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
watchOS
Apple iOS
iPadOS
tvOS
WebKitGTK+
WPE WebKit
Apple Safari
How to mitigate CVE-2023-23496
watchOS - update to 9.3 20S648
Apple Safari - update to 16.3
Apple iOS - addressed in versions 15.7.2 19H218, 16.3 20D47
iPadOS - addressed in versions 15.7.2 19H218, 16.3 20D47
tvOS - update to 16.3 20K650
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple tvOS
- Remote code execution in WebKitGTK+ and WPE WebKit
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15