CVE-2023-32393: High severity tvos vulnerability
Processing web content may lead to arbitrary code execution.
Reference: https://webkitgtk.org/security/WSA-2023-0006.html
Other sources
The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. Processing web content may lead to arbitrary code execution.
— Ubuntu
WebKit. The issue was addressed with improved memory handling
— Apple
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-32438
- CVE-2023-23499
- CVE-2023-23520
- CVE-2023-41990
- CVE-2023-23519
- CVE-2023-23500
- CVE-2023-23502
- CVE-2023-23504
- CVE-2023-23503
- CVE-2023-23512
- CVE-2023-23511
- CVE-2023-32393
- CVE-2022-0108
- CVE-2023-23496
- CVE-2023-23518
- CVE-2023-23517
- CVE-2023-23505
- CVE-2022-42915
- CVE-2022-42916
- CVE-2022-32221
- CVE-2022-35260
- CVE-2023-23539
- CVE-2023-23513
- CVE-2023-23493
- CVE-2023-23530
- CVE-2023-23531
- CVE-2023-23507
- CVE-2023-23516
- CVE-2023-23506
- CVE-2023-23498
- CVE-2023-28208
- CVE-2023-23497
- CVE-2023-23510
- CVE-2022-3705
- CVE-2023-23501
- CVE-2023-23508
Frequently Asked Questions
What is CVE-2023-32393?
CVE-2023-32393 is a vulnerability in WebKit that could lead to arbitrary code execution when processing web content.
How severe is CVE-2023-32393?
CVE-2023-32393 has a severity rating of 8.8 (high).
What software is affected by CVE-2023-32393?
The affected software includes WebKit versions up to 2.40.4-0ubuntu0.22.04.1, watchOS up to version 9.3, tvOS up to version 16.3, macOS Ventura up to version 13.2, iOS up to version 16.3, and iPadOS up to version 16.3.
How can I fix CVE-2023-32393?
To fix CVE-2023-32393, you should update the affected software to watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3, and iPadOS 16.3 or later versions.
Where can I find more information about CVE-2023-32393?
You can find more information about CVE-2023-32393 on the Apple support website.