cbcvebase.
CVE-2023-32409
published 2023-06-23

CVE-2023-32409: The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari…

PriorityP185high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-06-12
Exploited in the wild
EPSS
16.53%
96.6th percentile
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.

Affected

22 ranges
VendorProductVersion rangeFixed in
appleios_15.7.8_and_ipados
appleios_16.5_and_ipados
appleios_and_ipados>= unspecified < 15.715.7
appleios_and_ipados>= unspecified < 16.516.5
appleipados>= 15.0 < 15.7.815.7.8
appleipados>= 16.0 < 16.516.5
appleiphone_os>= 15.0 < 15.7.815.7.8
appleiphone_os>= 16.0 < 16.516.5
applemacos>= 13.0 < 13.413.4
applemacos>= unspecified < 13.413.4
applemacos_ventura
applesafari< 16.516.5
applesafari
applesafari>= unspecified < 16.516.5
appletvos< 16.516.5
appletvos
appletvos>= unspecified < 16.516.5
applewatchos< 9.59.5
applewatchos
applewatchos>= unspecified < 9.59.5
debianwebkit2gtk< webkit2gtk 2.42.0-1 (bookworm)webkit2gtk 2.42.0-1 (bookworm)
debianwpewebkit< webkit2gtk 2.42.0-1 (bookworm)webkit2gtk 2.42.0-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides in the WebGPU component of WebKit; detection should focus on anomalous GPU process activity or sandbox escape attempts originating from WebKit's GPU process on affected Apple platforms.
  • Apple confirmed active exploitation; treat any unpatched Apple device running Safari, iOS/iPadOS <16.5, macOS Ventura <13.4, tvOS <16.5, or watchOS <9.5 as high-risk and prioritize patching/detection.
  • ·Red Hat Linux platforms are not affected; WebkitGTK as shipped in RHEL 6, 7, 8, and 9 does not use the GPU process affected by this vulnerability, so Linux-based detections are not applicable.

CVSS provenance

nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
osv8.6HIGH
vulncheck8.6HIGH
cisa8.6HIGH
vendor_debian8.6LOW
vendor_redhat8.6HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.