cbcvebase.
CVE-2023-32435
published 2023-06-23

CVE-2023-32435: A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS…

PriorityP188high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
EPSS
22.95%
97.5th percentile
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.

Affected

16 ranges
VendorProductVersion rangeFixed in
appleios_15.7.7_and_ipados
appleios_16.4_and_ipados
appleios_and_ipados>= unspecified < 15.715.7
appleios_and_ipados>= unspecified < 16.416.4
appleipados< 15.7.715.7.7
appleipados>= 16.0 < 16.416.4
appleiphone_os< 15.7.715.7.7
appleiphone_os>= 16.0 < 16.416.4
applemacos>= 13.0 < 13.313.3
applemacos>= unspecified < 13.313.3
applemacos_ventura
applesafari< 16.416.4
applesafari
applesafari>= unspecified < 16.416.4
debianwebkit2gtk< webkit2gtk 2.40.0-1 (bookworm)webkit2gtk 2.40.0-1 (bookworm)
debianwpewebkit< webkit2gtk 2.40.0-1 (bookworm)webkit2gtk 2.40.0-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-32435 is exploited as part of the Operation Triangulation attack chain: the Safari exploit uses CVE-2023-32435 to execute a shellcode, triggered after a prior stage forwards an invisible Safari process to a web page with the next stage exploit.
  • CVE-2023-32435 is a WebKit memory corruption vulnerability in the component 'WebKit'; detection should focus on anomalous web content processing leading to memory corruption on iOS/iPadOS/macOS/Safari.
  • CVE-2023-32435 was used in a zero-click iMessage attack chain targeting iOS versions up to iOS 16.2; the full chain involves a malicious iMessage attachment processed without user interaction, followed by multiple exploit stages including a Safari exploit leveraging this CVE.
  • Prior to the Safari/CVE-2023-32435 stage, the attack launches IMAgent to clear exploitation artifacts; monitor for unexpected IMAgent process launches injecting payloads as a precursor indicator.
  • The JavaScript exploit used in the chain (preceding CVE-2023-32435 stage) is heavily obfuscated with ~11,000 lines of code targeting JavaScriptCore and kernel memory; detection of large obfuscated JS blobs interacting with JavaScriptCore internals may indicate this attack.
  • ·CVE-2023-32435 was actively exploited in the wild against iOS versions released before iOS 15.7; the exploit chain was designed to work on iOS versions up to iOS 16.2.
  • ·The Triangulation spyware (which uses CVE-2023-32435) is removed from devices after a reboot, limiting persistence-based detection approaches.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.