cbcvebase.
CVE-2023-41993
published 2023-09-21

CVE-2023-41993: The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-10-16
Exploited in the wild
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_16.7_and_ipados
appleios_17.0.1_and_ipados
appleipados< 17.0.117.0.1
appleiphone_os< 17.0.117.0.1
applemacos< 14.014.0
applemacos>= unspecified < 1414
applemacos_sonoma
applesafari
applesafari
debiandebian_linux
debiandebian_linux
debianwebkit2gtk< webkit2gtk 2.42.1-1~deb12u1 (bookworm)webkit2gtk 2.42.1-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.42.1-1~deb12u1 (bookworm)webkit2gtk 2.42.1-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
oraclegraalvm
oraclegraalvm
oraclejdk
oraclejre
webkitgtkwebkitgtk< 2.42.22.42.2

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH