cbcvebase.
CVE-2023-32439
published 2023-06-23

CVE-2023-32439: A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura…

PriorityP190high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-07-14
Exploited in the wild
EPSS
23.79%
97.6th percentile
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Affected

17 ranges
VendorProductVersion rangeFixed in
appleios_15.7.7_and_ipados
appleios_16.5.1_and_ipados
appleios_and_ipados>= unspecified < 15.715.7
appleios_and_ipados>= unspecified < 16.516.5
appleipados< 15.7.715.7.7
appleipados>= 16.0 < 16.5.116.5.1
appleiphone_os< 15.7.715.7.7
appleiphone_os>= 16.0 < 16.5.116.5.1
applemacos>= 13.0 < 13.4.113.4.1
applemacos>= unspecified < 13.413.4
applemacos_ventura
applesafari< 16.5.116.5.1
applesafari
applesafari>= unspecified < 16.516.5
debianwebkit2gtk< webkit2gtk 2.40.3-2~deb12u1 (bookworm)webkit2gtk 2.40.3-2~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.40.3-2~deb12u1 (bookworm)webkit2gtk 2.40.3-2~deb12u1 (bookworm)
webkitgtkwebkitgtk< 2.42.32.42.3

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-32439 is a WebKit type confusion vulnerability actively exploited in the wild as part of Operation Triangulation, a wide iPhone campaign targeting Russian citizens. Detection should focus on exploitation of WebKit's JIT engine via maliciously crafted web content.
  • The vulnerability is triggered through processing maliciously crafted web content in WebKit, including Apple Safari and any non-Apple products relying on WebKit for HTML parsing. Monitor for suspicious web content processing activity in WebKit-based browsers.
  • The vulnerability relies on the JIT engine within WebKit. Disabling JIT in WebKit/webkitgtk mitigates exploitation. Environments with JIT disabled (as done for CVE-2023-32435 and CVE-2023-32439 fixes in RHEL) are not affected.
  • ·CISA mandated remediation due date was 2023-07-14; unpatched Apple iOS, iPadOS, macOS, and Safari instances remain at risk. Patch to iOS 16.5.1 / iPadOS 16.5.1, iOS 15.7.7 / iPadOS 15.7.7, macOS Ventura 13.4.1, or Safari 16.5.1 at minimum.
  • ·Debian webkitgtk packages are resolved in bookworm (2.40.3-2~deb12u1), bullseye (2.40.3-2~deb11u1), forky/sid/trixie (2.40.3-1). Unpatched Debian systems running older webkitgtk versions remain vulnerable.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.