CVE-2023-42916: Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
— Ubuntu
Apple iOS, iPadOS, macOS, and Safari WebKit contain an out-of-bounds read vulnerability that may disclose sensitive information when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
AVEVideoEncoder. This issue was addressed with improved redaction of sensitive information.
— Apple
ImageIO. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-0ubuntu0.23.04.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1Fixed in 2.42.5-1~deb12u1Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.1.2 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.2 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 17.1.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.1.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.1.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.8.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.2 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.44.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.44.1-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42916
- CVE-2023-42917
- CVE-2023-42884
- CVE-2023-42898
- CVE-2023-42899
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-42936
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-42890
- CVE-2023-42883
- CVE-2023-42950
- CVE-2022-48618
- CVE-2024-23222
- CVE-2023-42937
- CVE-2023-42919
- CVE-2023-42888
- CVE-2023-42896
- CVE-2023-42962
- CVE-2023-42922
- CVE-2023-42974
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-42916.
What is the title of this vulnerability?
The title of this vulnerability is 'WebKit. An out-of-bounds read was addressed with improved input validation.'
What is the severity of CVE-2023-42916?
The severity of CVE-2023-42916 is not mentioned in the description.
How can this vulnerability be exploited?
This vulnerability can be exploited by processing web content, which may disclose sensitive information.
How can I fix this vulnerability?
To fix this vulnerability, update to the latest versions of affected software: iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2.