cbcvebase.
CVE-2023-23529
published 2023-02-27

CVE-2023-23529: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura…

PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-03-07
Exploited in the wild
EPSS
9.50%
94.9th percentile
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleios_15.7.4_and_ipados
appleios_16.3.1_and_ipados
appleios_and_ipados>= unspecified < 16.316.3
appleios_and_ipados>= unspecified < 15.715.7
appleipados< 15.7.415.7.4
appleipados>= 16.0 < 16.3.116.3.1
appleiphone_os< 15.7.415.7.4
appleiphone_os>= 16.0 < 16.3.116.3.1
applemacos>= 13.0 < 13.2.113.2.1
applemacos>= unspecified < 13.213.2
applemacos_ventura
applesafari< 16.316.3
applesafari
applesafari>= unspecified < 16.316.3
debianwebkit2gtk< webkit2gtk 2.38.5-1 (bookworm)webkit2gtk 2.38.5-1 (bookworm)
debianwpewebkit< webkit2gtk 2.38.5-1 (bookworm)webkit2gtk 2.38.5-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by processing maliciously crafted web content via WebKit; monitor for suspicious web content delivery targeting WebKit-based browsers (Safari, Epiphany, WebKitGTK-based apps)
  • This vulnerability could impact HTML parsers beyond Apple products; scope detection to any non-Apple products relying on WebKit for HTML processing
  • The root cause is a type confusion in WebKit's JavaScript engine (JSC/DFG JIT); consider monitoring for JIT-related crashes or anomalous JavaScript engine behavior in WebKit processes
  • ·Setting the environment variable JSC_useDFGJIT=0 will mitigate this issue on WebKitGTK/Linux platforms by disabling the DFG JIT compiler where the type confusion occurs
  • ·Red Hat confirmed no known exploitation on Linux platforms at time of advisory; Linux-based WebKitGTK deployments may have lower immediate risk but remain vulnerable
  • ·webkitgtk (RHEL 6) and webkitgtk3 (RHEL 7) are marked 'Will not fix' by Red Hat; these platforms will remain permanently vulnerable

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.