Buffer overflow in WebKitGTK+ and WPE WebKit - CVE-2023-32409
Published: May 18, 2023 / Updated: May 18, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in WebKit. A remote attacker can trick the victim to visit a specially crafted web page, trigger memory corruption and break out of Web Content sandbox.
Note, the vulnerability is being actively exploited in the wild.
Affected software
WPE WebKit
watchOS
macOS
iPadOS
Apple iOS
tvOS
openEuler
Apple Safari
webkit2gtk3-debugsource
webkit2gtk3-help
webkit2gtk3-jsc-devel
webkit2gtk3-devel
webkit2gtk3-debuginfo
webkit2gtk3-jsc
webkit2gtk3
How to mitigate CVE-2023-32409
macOS - update to 13.4 22F66
iPadOS - addressed in versions 15.7.8 19H364, 16.5 20F66
Apple iOS - addressed in versions 15.7.8 19H364, 16.5 20F66
Apple Safari - update to 16.5
tvOS - update to 16.5 20L562
webkit2gtk3-debugsource - update to 2.36.3-4
webkit2gtk3-help - update to 2.36.3-4
webkit2gtk3-jsc-devel - update to 2.36.3-4
webkit2gtk3-devel - update to 2.36.3-4
webkit2gtk3-debuginfo - update to 2.36.3-4
webkit2gtk3-jsc - update to 2.36.3-4
webkit2gtk3 - update to 2.36.3-4
External References
Related Security Bulletins
- Multiple vulnerabilities in WebKitGTK and WPE WebKit
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in Apple Safari
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- openEuler 22.03 LTS update for webkit2gtk3
- openEuler 22.03 LTS SP1 update for webkit2gtk3