CVE-2023-32373: Apple Multiple Products WebKit Use-After-Free Vulnerability
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with improved checks.
— Apple
Accounts. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.2 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.4-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.40.4-0ubuntu0.23.04.1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.2-1~deb11u1Fixed in 2.42.5-1~deb11u1Fixed in 2.42.2-1~deb12u1Fixed in 2.42.5-1~deb12u1Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1Fixed in 2.42.5-1.1 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 16.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 9.5 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 16.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.7.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.7.6 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.2-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.2-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32400
- CVE-2023-34352
- CVE-2023-32411
- CVE-2023-32399
- CVE-2023-28191
- CVE-2023-32392
- CVE-2023-32372
- CVE-2023-32384
- CVE-2023-32354
- CVE-2023-32420
- CVE-2023-27930
- CVE-2023-32398
- CVE-2023-32413
- CVE-2023-32352
- CVE-2023-32428
- CVE-2023-32407
- CVE-2023-32368
- CVE-2023-32403
- CVE-2023-32437
- CVE-2023-32390
- CVE-2023-32357
- CVE-2023-32432
- CVE-2023-32391
- CVE-2023-32404
- CVE-2023-32394
- CVE-2023-32422
- CVE-2023-32376
- CVE-2023-28202
- CVE-2023-32412
- CVE-2023-32408
- CVE-2023-32415
- CVE-2023-32402
- CVE-2023-32423
- CVE-2023-32409
- CVE-2023-28204
- CVE-2023-32373
- CVE-2023-32389
- CVE-2023-32388
- CVE-2023-32425
- CVE-2023-32417
- CVE-2023-32379
- CVE-2023-32383
- CVE-2023-32371
- CVE-2023-32386
- CVE-2023-32360
- CVE-2023-32387
- CVE-2023-32414
- CVE-2023-32410
- CVE-2023-27940
- CVE-2023-29469
- CVE-2023-42869
- CVE-2023-32369
- CVE-2023-32405
- CVE-2023-42958
- CVE-2023-32375
- CVE-2023-32382
- CVE-2023-32380
- CVE-2023-32355
- CVE-2023-32385
- CVE-2023-32395
- CVE-2023-32401
- CVE-2023-32363
- CVE-2023-32367
- CVE-2023-32397
- CVE-2023-22809
- CVE-2023-32419
- CVE-2023-32365
- CVE-2023-23532
- CVE-2023-28181
Frequently Asked Questions
What is CVE-2023-32373?
CVE-2023-32373 is a use-after-free vulnerability in Apple Multiple Products WebKit.
What is the severity of CVE-2023-32373?
The severity of CVE-2023-32373 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2023-32373?
The affected software versions include watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5, and iPadOS 16.5.
How can I fix CVE-2023-32373?
To fix CVE-2023-32373, update your software to the fixed versions: watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5, and iPadOS 16.5.
Where can I find more information about CVE-2023-32373?
You can find more information about CVE-2023-32373 on the Apple support website: [Link](https://support.apple.com/en-us/HT213757), [Link](https://support.apple.com/en-us/HT213758), [Link](https://support.apple.com/en-us/HT213761).