cbcvebase.
CVE-2023-42916
published 2023-11-30

CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2…

PriorityP179medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-12-25
Exploited in the wild
EPSS
17.82%
96.8th percentile
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Affected

25 ranges
VendorProductVersion rangeFixed in
appleios_15.8.1_and_ipados
appleios_16.7.3_and_ipados
appleios_17.1.2_and_ipados
appleios_and_ipados>= unspecified < 17.117.1
appleipados< 15.8.115.8.1
appleipados>= 16.0 < 16.7.316.7.3
appleipados>= 17.0 < 17.1.217.1.2
appleiphone_os< 15.8.115.8.1
appleiphone_os>= 16.0 < 16.7.316.7.3
appleiphone_os>= 17.0 < 17.1.217.1.2
applemacos>= 14.0 < 14.1.214.1.2
applemacos>= unspecified < 14.114.1
applemacos_sonoma
applesafari< 17.1.217.1.2
applesafari
applesafari>= unspecified < 17.117.1
appletvos
applewatchos
debiandebian_linux
debiandebian_linux
debianwebkit2gtk< webkit2gtk 2.42.3-1~deb12u1 (bookworm)webkit2gtk 2.42.3-1~deb12u1 (bookworm)
debianwpewebkit< webkit2gtk 2.42.3-1~deb12u1 (bookworm)webkit2gtk 2.42.3-1~deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
webkitgtkwebkitgtk< 2.42.32.42.3

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2023-42916 is a WebKit out-of-bounds read triggered by processing web content; exploitation was observed against iOS versions before iOS 16.7.1, meaning any device on iOS < 16.7.1 visiting attacker-controlled web content is a target
  • CVE-2023-42916 is co-exploited alongside CVE-2023-42917 (WebKit memory corruption / arbitrary code execution); detections should consider both vulnerabilities appearing together in the same attack chain
  • Exploitation of CVE-2023-42916 is consistent with state-sponsored spyware attack patterns targeting high-risk individuals (journalists, dissidents, opposition politicians) via WebKit-based browsers on iOS
  • Exploitation of CVE-2023-42916 was confirmed against iOS versions predating iOS 16.7.1 (released Oct. 10, 2023); threat hunting should focus on devices that had not applied the October 2023 patch
  • ·Apple has not publicly disclosed technical details, exploit samples, or attribution for CVE-2023-42916 exploitation; no hashes, domains, IPs, or network indicators are available from the provided sources
  • ·Patches were initially released for newer devices in November 2023 (iOS 17.1.2 / macOS Sonoma 14.1.2 / Safari 17.1.2) and later backported in January 2024 to older devices (iOS 16.7.6 / iPadOS 16.7.6); detection scope should cover both patch waves

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_oracle7.5HIGH
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.