CVE-2023-42917: Apple Multiple Products WebKit Memory Corruption Vulnerability
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Apple iOS, iPadOS, macOS, and Safari WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
— CISA
AVEVideoEncoder. This issue was addressed with improved redaction of sensitive information.
— Apple
ImageIO. The issue was addressed with improved checks.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1Fixed in 2.42.5-1~deb12u1Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1Fixed in 2.44.1-1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-0ubuntu0.22.04.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-0ubuntu0.23.04.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-0ubuntu0.23.10.1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3-1 - Upgrade
Upgrade
ubuntu/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.3 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.1.2 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 17.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 10.2 - Upgrade
Upgrade
Safarito a version that resolves this vulnerability.Fixed in 17.1.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.8.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.8.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.1.2 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.1.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.2 - Upgrade
Upgrade
redhat/webkitgtkto a version that resolves this vulnerability.Fixed in 2.42.3 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb11u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1~deb12u1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/webkit2gtkto a version that resolves this vulnerability.Fixed in 2.44.1-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.42.5-1 - Upgrade
Upgrade
debian/wpewebkitto a version that resolves this vulnerability.Fixed in 2.44.1-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42916
- CVE-2023-42917
- CVE-2023-42884
- CVE-2023-42898
- CVE-2023-42899
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-42936
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-42890
- CVE-2023-42883
- CVE-2023-42950
- CVE-2022-48618
- CVE-2024-23222
- CVE-2023-42937
- CVE-2023-42919
- CVE-2023-42888
- CVE-2023-42896
- CVE-2023-42962
- CVE-2023-42922
- CVE-2023-42974
Frequently Asked Questions
What is CVE-2023-42917?
CVE-2023-42917 is a memory corruption vulnerability in WebKit that allows for arbitrary code execution.
Which Apple products are affected by CVE-2023-42917?
Apple Safari, macOS Sonoma, iOS, and iPadOS versions up to and including 17.1.2 are affected by CVE-2023-42917.
How was CVE-2023-42917 fixed?
CVE-2023-42917 was fixed with improved locking in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2.
Is there a remedy available for CVE-2023-42917?
Yes, the remedy for CVE-2023-42917 is to update to iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, or Safari 17.1.2.
Where can I find more information about CVE-2023-42917?
You can find more information about CVE-2023-42917 in the following references: - [Apple Support - HT214031](https://support.apple.com/en-us/HT214031) - [Apple Support - HT214033](https://support.apple.com/en-us/HT214033) - [Apple Support - HT214032](https://support.apple.com/en-us/HT214032)