CVE-2023-28205: Apple Multiple Products WebKit Use-After-Free Vulnerability
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.7.5 and iPadOS 15.7.5, Safari 16.4.1, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Other sources
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 16.4.1, iOS 15.7.5 and iPadOS 15.7.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
CVE-2023-28205 (WebKit)
It is a use-after-free vulnerability that allows attackers to process maliciously crafted web content that may lead to arbitrary code execution.
By tricking targets into loading malicious websites under the control of attackers, it is possible to exploit the vulnerability, which could lead to the execution of malware on compromised systems. Maliciously designed web content can cause the execution of arbitrary code, giving attackers access to your device without your knowledge. Apple has fixed this vulnerability with improved memory management.
WebKit Bugzilla: 254797
https://seclists.org/fulldisclosure/2023/Apr/1 https://seclists.org/fulldisclosure/2023/Apr/2 https://seclists.org/fulldisclosure/2023/Apr/3
— Red Hat
WebKit. A use after free issue was addressed with improved memory management.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2023-28205?
CVE-2023-28205 is a use-after-free vulnerability in Apple Multiple Products WebKit that allows for arbitrary code execution.
Which products are affected by CVE-2023-28205?
The affected products include macOS Ventura 13.3.1, Safari 16.4.1, iOS 15.7.5, and iPadOS 15.7.5.
How can I fix the CVE-2023-28205 vulnerability on my Apple device?
You can fix the CVE-2023-28205 vulnerability by updating your device to iOS 15.7.5 or iPadOS 15.7.5, Safari 16.4.1, or macOS Ventura 13.3.1.
What is the severity of CVE-2023-28205?
CVE-2023-28205 has a severity rating of 8.8 (high).
Are there any references for CVE-2023-28205?
Yes, you can find references for CVE-2023-28205 at the following links: [Link 1](http://seclists.org/fulldisclosure/2023/Apr/1), [Link 2](http://seclists.org/fulldisclosure/2023/Apr/2), [Link 3](http://seclists.org/fulldisclosure/2023/Apr/3).