CVE-2023-42950: Use After Free
A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with improved state management.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
AppleEvents. This issue was addressed with improved redaction of sensitive information.
— Apple
AppleGraphicsControl. Multiple memory corruption issues were addressed with improved input validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-42874
- CVE-2023-42937
- CVE-2023-42919
- CVE-2023-42894
- CVE-2023-42901
- CVE-2023-42902
- CVE-2023-42912
- CVE-2023-42903
- CVE-2023-42904
- CVE-2023-42905
- CVE-2023-42906
- CVE-2023-42907
- CVE-2023-42908
- CVE-2023-42909
- CVE-2023-42910
- CVE-2023-42911
- CVE-2023-42926
- CVE-2023-42882
- CVE-2023-42881
- CVE-2023-42924
- CVE-2023-42896
- CVE-2023-42884
- CVE-2023-45866
- CVE-2023-42900
- CVE-2023-42886
- CVE-2023-38545
- CVE-2023-38039
- CVE-2023-38546
- CVE-2023-42931
- CVE-2023-42892
- CVE-2023-42922
- CVE-2023-42898
- CVE-2023-42899
- CVE-2023-42888
- CVE-2023-42891
- CVE-2023-42974
- CVE-2023-42914
- CVE-2023-42893
- CVE-2023-3618
- CVE-2020-19185
- CVE-2020-19186
- CVE-2020-19187
- CVE-2020-19188
- CVE-2020-19189
- CVE-2020-19190
- CVE-2023-42887
- CVE-2023-42936
- CVE-2023-40390
- CVE-2023-42842
- CVE-2023-42930
- CVE-2023-42913
- CVE-2023-42932
- CVE-2023-42947
- CVE-2023-40389
- CVE-2023-5344
- CVE-2023-42890
- CVE-2023-42883
- CVE-2023-42950
- CVE-2023-42956
- CVE-2023-42916
- CVE-2023-42917
- CVE-2023-42941
- CVE-2023-42962
- CVE-2023-42923
- CVE-2023-42897
- CVE-2023-43010
Frequently Asked Questions
What is the severity of CVE-2023-42950?
CVE-2023-42950 is classified as a critical vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2023-42950?
To fix CVE-2023-42950, update Safari or the affected WebKit packages to their latest versions as specified by your vendor.
Which versions are affected by CVE-2023-42950?
CVE-2023-42950 affects Safari prior to version 17.2 and several versions of WebKitGTK and WPEWebKit.
What platforms are impacted by CVE-2023-42950?
CVE-2023-42950 impacts multiple Apple platforms including iOS, iPadOS, macOS, tvOS, and watchOS, as well as certain Ubuntu and Debian packages.
What does CVE-2023-42950 exploit?
CVE-2023-42950 exploits a use after free vulnerability in WebKit that can be triggered through maliciously crafted web content.