cbcvebase.
CVE-2023-32402
published 2023-06-23

CVE-2023-32402: An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5…

PriorityP179medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.72%
49.7th percentile
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleios_16.5_and_ipados
appleios_and_ipados>= unspecified < 16.516.5
appleipados>= 16.0 < 16.516.5
appleiphone_os>= 16.0 < 16.516.5
applemacos>= 13.0 < 13.413.4
applemacos>= unspecified < 13.413.4
applemacos_ventura
applesafari< 16.516.5
applesafari
applesafari>= unspecified < 16.516.5
appletvos< 16.516.5
appletvos
appletvos>= unspecified < 16.516.5
applewatchos< 9.59.5
applewatchos
applewatchos>= unspecified < 9.59.5

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via processing of malicious web content in WebKit; monitor for suspicious web content rendering activity across affected Apple platforms (iOS, iPadOS, macOS, tvOS, watchOS, Safari)
  • The affected component is WebKit; focus detection on WebKit-based browser processes (e.g., Safari, WebContent process) for out-of-bounds read anomalies
  • ·No public proof-of-concept, exploit code, specific payloads, hashes, network indicators, or signatures were referenced in any source. All provided sources are Apple advisory pages with no operational IOCs.
  • ·Fixed versions are: watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Detection should focus on identifying unpatched systems running versions prior to these.

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vulncheck6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.