CVE-2023-42843: Use After Free
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
Other sources
Automation. The issue was addressed with improved checks.
— Apple
Contacts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Core Recents. The issue was resolved by sanitizing logging
— Apple
CoreAnimation. The issue was addressed with improved memory handling.
— Apple
FairPlay. The issue was addressed with improved bounds checks.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-30774
- CVE-2023-40444
- CVE-2023-42952
- CVE-2023-42945
- CVE-2023-41072
- CVE-2023-42857
- CVE-2023-40449
- CVE-2023-42823
- CVE-2023-41989
- CVE-2023-42854
- CVE-2023-40413
- CVE-2023-42834
- CVE-2023-42844
- CVE-2023-42953
- CVE-2023-40416
- CVE-2023-42848
- CVE-2023-40423
- CVE-2023-38403
- CVE-2023-42849
- CVE-2023-42850
- CVE-2023-40446
- CVE-2023-42942
- CVE-2023-42861
- CVE-2023-42935
- CVE-2023-40408
- CVE-2023-40405
- CVE-2023-28826
- CVE-2023-42856
- CVE-2023-40404
- CVE-2023-42859
- CVE-2023-42877
- CVE-2023-42840
- CVE-2023-42853
- CVE-2023-42860
- CVE-2023-42889
- CVE-2023-42847
- CVE-2023-42845
- CVE-2023-42841
- CVE-2023-42873
- CVE-2023-42838
- CVE-2023-42835
- CVE-2023-41977
- CVE-2023-42438
- CVE-2023-42836
- CVE-2023-42839
- CVE-2023-42878
- CVE-2023-41982
- CVE-2023-41997
- CVE-2023-41988
- CVE-2023-42946
- CVE-2023-36191
- CVE-2023-40421
- CVE-2023-42842
- CVE-2023-4733
- CVE-2023-4734
- CVE-2023-4735
- CVE-2023-4736
- CVE-2023-4738
- CVE-2023-4750
- CVE-2023-4751
- CVE-2023-4752
- CVE-2023-4781
- CVE-2023-41254
- CVE-2023-40447
- CVE-2023-41976
- CVE-2023-42852
- CVE-2023-42843
- CVE-2023-41983
- CVE-2023-41975
- CVE-2023-42858
- CVE-2023-42928
- CVE-2023-42846
- CVE-2023-42951
- CVE-2023-42855
- CVE-2023-40445
- CVE-2023-42939
- CVE-2023-32359
Frequently Asked Questions
What is the severity of CVE-2023-42843?
CVE-2023-42843 has been categorized as a medium severity vulnerability.
How do I fix CVE-2023-42843?
To fix CVE-2023-42843, update your device to iOS 16.7.2, iPadOS 16.7.2, iOS 17.1, iPadOS 17.1, Safari 17.1, or macOS Sonoma 14.1.
What systems are affected by CVE-2023-42843?
CVE-2023-42843 affects Apple Safari, iOS, iPadOS, and macOS versions prior to the specified updates.
What type of vulnerability is CVE-2023-42843?
CVE-2023-42843 is an inconsistent user interface issue that may lead to address bar spoofing.
Is there a known exploit for CVE-2023-42843?
There are no known public exploits specifically for CVE-2023-42843, but users are advised to apply the updates to mitigate risks.