cbcvebase.
CVE-2023-41993
published 2023-09-21

CVE-2023-41993: The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is…

PriorityP189high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-16
Exploited in the wild
EPSS
29.18%
97.9th percentile
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Affected

21 ranges
VendorProductVersion rangeFixed in
appleios_16.7_and_ipados
appleios_17.0.1_and_ipados
appleipados< 17.0.117.0.1
appleiphone_os< 17.0.117.0.1
applemacos< 14.014.0
applemacos>= unspecified < 1414
applemacos_sonoma
applesafari
applesafari
debiandebian_linux
debiandebian_linux
debianwebkit2gtk< webkit2gtk 2.42.1-1~deb12u1 (bookworm)webkit2gtk 2.42.1-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.42.1-1~deb12u1 (bookworm)webkit2gtk 2.42.1-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
oraclegraalvm
oraclegraalvm
oraclejdk
oraclejre
webkitgtkwebkitgtk< 2.42.22.42.2

Detection & IOCsextracted from sources · hover to see the quote

domaintrack-adv[.]com
urlhttps://track-adv[.]com/market-analytics.php?pc=1
domainceo-adviser[.]com
urlhttps://ceo-adviser[.]com/fb-connect.php?online=1
domainsec-flare[.]com
urlhttps://track-adv[.]com/analytics.php?personalization_id=
otherIndexedDB database name: minus (iOS exploit)
otherUnique identifier format: e.g., 1lwuzddaxoom5ylli37v90kj (26-char alphanumeric, passed as initial GET parameter)
commandgcr=1 (HTTP request parameter used to retrieve AES decryption key from C2)
processdacsiloscope (function using read/write primitives to collect device information)
  • Detect iframe injection on Mongolian government sites loading attacker-controlled domains (track-adv[.]com, ceo-adviser[.]com) via hidden iframe in page HTML.
  • Monitor for WebSocket connections to attacker-controlled IPs originating from Safari/WebKit processes, particularly where m_universalAccess is manipulated to exfiltrate cookies from targeted domains.
  • Alert on DNS/HTTP requests to the hard-coded cookie-stealer target list, especially from mobile browser processes: webmail.mfa.gov.mn/owa/auth, accounts.google.com, login.microsoftonline.com, mail.google.com, linkedin.com, office.com, login.live.com, outlook.live.com, login.yahoo.com, mail.yahoo.com, facebook.com, github.com, icloud.com.
  • Flag HTTP responses containing AES-encrypted payloads or the literal value '0' from exploit-staging servers in response to reconnaissance GET requests — the server replies with either an AES encrypted next stage or 0.
  • The exploit targets iOS 16.6.1 and older; devices with Lockdown Mode enabled are not affected even on vulnerable versions — use MDM telemetry to identify unpatched devices without Lockdown Mode as high-priority targets.
  • Look for calls to WebCore::NetworkStorageSession::getAllCookies() originating from browser renderer processes on newer iOS versions as an indicator of cookie-stealer payload execution.
  • The underlying bug is in FTL JIT compilation; Red Hat notes that disabling JIT (as done after CVE-2023-32435/CVE-2023-32439 fixes) mitigates this vulnerability in webkitgtk — consider JIT-disabled WebKit builds as a detection/mitigation signal.
  • ·The exploit only works on iOS 16.6.1 and older; iOS 16.7+ and devices with Lockdown Mode enabled are not vulnerable, so detections should be scoped accordingly.
  • ·TAG was unable to capture the full Predator implant payload, so post-exploitation IOCs for the full spyware are incomplete.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH
cisa8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_oracle7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.