CVE-2023-23529: Apple Multiple Products WebKit Type Confusion Vulnerability
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Other sources
Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
This issue occurs when processing maliciously crafted web content in WebKit. This may allow a remote attacker to create a specially crafted web page, trick the victim into opening it, trigger type confusion, and execute arbitrary code on the target system.
— Red Hat
WebKit. A type confusion issue was addressed with improved checks.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-23514
- CVE-2023-23524
- CVE-2023-23522
- CVE-2023-23529
- CVE-2023-23518
- CVE-2023-23517
- CVE-2023-23496
- CVE-2022-0108
- CVE-2023-23541
- CVE-2023-27961
- CVE-2023-23543
- CVE-2023-27936
- CVE-2023-23537
- CVE-2023-27956
- CVE-2023-32366
- CVE-2023-27928
- CVE-2023-27946
- CVE-2023-23535
- CVE-2023-28200
- CVE-2023-27941
- CVE-2023-27969
- CVE-2023-23536
- CVE-2023-28185
- CVE-2023-41075
- CVE-2023-27949
- CVE-2023-27950
- CVE-2023-28182
- CVE-2023-27963
- CVE-2023-27954
- CVE-2023-28198
- CVE-2023-32358
- CVE-2023-28201
Frequently Asked Questions
What is CVE-2023-23529?
CVE-2023-23529 is a type confusion vulnerability in Apple Multiple Products, including iOS, iPadOS, and Safari, that could allow arbitrary code execution.
How does CVE-2023-23529 affect Apple products?
CVE-2023-23529 affects Apple products including iOS, iPadOS, and Safari.
What is the severity of CVE-2023-23529?
CVE-2023-23529 has a severity rating of 8.8 (high).
How can I fix CVE-2023-23529?
To fix CVE-2023-23529, update to the latest available version of iOS, iPadOS, and macOS Ventura, as well as Safari.
Where can I find more information about CVE-2023-23529?
You can find more information about CVE-2023-23529 on the Apple support website.