CVE-2023-43010
published 2026-03-12CVE-2023-43010: The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS…
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.89%
55.2th percentile
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.8.7_and_ipados | — | — |
| apple | ios_16.7.15_and_ipados | — | — |
| apple | ios_17.2_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 17.2 | 17.2 |
| apple | ios_and_ipados | >= unspecified < 16.7.15 | 16.7.15 |
| apple | ios_and_ipados | >= unspecified < 15.8.7 | 15.8.7 |
| apple | ipados | < 15.8.7 | 15.8.7 |
| apple | ipados | >= 16.0 < 16.7.15 | 16.7.15 |
| apple | ipados | >= 17.0 < 17.2 | 17.2 |
| apple | iphone_os | < 15.8.7 | 15.8.7 |
| apple | iphone_os | >= 16.0 < 16.7.15 | 16.7.15 |
| apple | iphone_os | >= 17.0 < 17.2 | 17.2 |
| apple | macos | < 14.2 | 14.2 |
| apple | macos | >= unspecified < 14.2 | 14.2 |
| apple | macos_sonoma | — | — |
| apple | safari | < 17.2 | 17.2 |
| apple | safari | — | — |
| apple | safari | >= unspecified < 17.2 | 17.2 |
| debian | webkit2gtk | < webkit2gtk 2.44.1-1~deb12u1 (bookworm) | webkit2gtk 2.44.1-1~deb12u1 (bookworm) |
| debian | wpewebkit | < webkit2gtk 2.44.1-1~deb12u1 (bookworm) | webkit2gtk 2.44.1-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
webkitgtk: Processing maliciously crafted web content may lead to memory corruption
vendor_redhat·2026-03-18·CVSS 8.8
CVE-2023-43010 [HIGH] CWE-120 webkitgtk: Processing maliciously crafted web content may lead to memory corruption
webkitgtk: Processing maliciously crafted web content may lead to memory corruption
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
Statement: To exploit this issue, an attacker needs to trick a user into processing or loading malicious web content. Due to this reason, this flaw has been rated with an important severity.
Additionally, this issue can cause memory corruption and the possibility of remote code execution is not discarded.
Mitigati
Apple
CVE-2023-43010: iOS 15.8.7 and iPadOS 15.8.7
vendor_apple·2026-03-11·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: iOS 15.8.7 and iPadOS 15.8.7
Apple Security Update: About the security content of iOS 15.8.7 and iPadOS 15.8.7
Product: iOS 15.8.7 and iPadOS
Version: 15.8.7
CVE: CVE-2023-43010
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption. This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023. This update brings that fix to devices that cannot update to the latest iOS version.
Description: The issue was addressed with improved memory handling.
Apple
CVE-2023-43010: iOS 16.7.15 and iPadOS 16.7.15
vendor_apple·2026-03-11·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: iOS 16.7.15 and iPadOS 16.7.15
Apple Security Update: About the security content of iOS 16.7.15 and iPadOS 16.7.15
Product: iOS 16.7.15 and iPadOS
Version: 16.7.15
CVE: CVE-2023-43010
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption. This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023. This update brings that fix to devices that cannot update to the latest iOS version.
Description: The issue was addressed with improved memory handling.
Apple
CVE-2023-43010: iOS 17.2 and iPadOS 17.2
vendor_apple·2023-12-11·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: iOS 17.2 and iPadOS 17.2
Apple Security Update: About the security content of iOS 17.2 and iPadOS 17.2
Product: iOS 17.2 and iPadOS
Version: 17.2
CVE: CVE-2023-43010
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption.
Description: The issue was addressed with improved memory handling.
Apple
CVE-2023-43010: macOS Sonoma 14.2
vendor_apple·2023-12-11·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-43010
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption.
Description: The issue was addressed with improved memory handling.
Apple
CVE-2023-43010: Safari 17.2
vendor_apple·2023-12-11·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: Safari 17.2
Apple Security Update: About the security content of Safari 17.2
Product: Safari
Version: 17.2
CVE: CVE-2023-43010
Component: WebKit
Impact: Processing maliciously crafted web content may lead to memory corruption.
Description: The issue was addressed with improved memory handling.
Debian
CVE-2023-43010: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in iO...
vendor_debian·2023·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: webkit2gtk - The issue was addressed with improved memory handling. This issue is fixed in iO...
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
Scope: local
bookworm: resolved (fixed in 2.44.1-1~deb12u1)
bullseye: resolved (fixed in 2.44.1-1~deb11u1)
forky: resolved (fixed in 2.44.0-1)
sid: resolved (fixed in 2.44.0-1)
trixie: resolved (fixed in 2.44.0-1)
GHSA
GHSA-4v27-f65g-fr6x: The issue was addressed with improved memory handling
ghsa_unreviewed·2026-03-12
CVE-2023-43010 [HIGH] CWE-787 GHSA-4v27-f65g-fr6x: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
OSV
CVE-2023-43010: The issue was addressed with improved memory handling
osv·2026-03-12·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010: The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple patches older iPhones and iPads against Coruna exploits
blogs_bleepingcomputer·2026-03-12·CVSS 7.8
CVE-2023-41974 [HIGH] Apple patches older iPhones and iPads against Coruna exploits
## Apple patches older iPhones and iPads against Coruna exploits
## Sergiu Gatlan
Apple said the patches will fix iOS security issues targeted by multiple exploit chains, many used in zero-day attacks aiming to help attackers escalate permissions to Kernel privileges or gain remote code execution on vulnerable devices.
The list of vulnerabilities addressed by these backported security patches includes:
CVE-2023-41974: A Kernel use-after-free issue addressed with improved memory management
CVE-2024-23222: A WekKit type confusion issue addressed with improved checks
CVE-2023-43000: A WebKit use-after-free issue addressed with improved memory management
CVE-2023-43010: A WebKit issue was addressed with improved memory handling
The list of devices impacted by these vulnerabilities is a
Wiz
CVE-2023-43010 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2023-43010 [HIGH] CVE-2023-43010 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2023-43010 :
Apple Safari vulnerability analysis and mitigation
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
Source : NVD
## 8.8
Score
Published March 12, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Apple Safari
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
WebKit
libwebkit2gtk3-lang
Sources
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Mar 21, 2
https://support.apple.com/en-us/120300https://support.apple.com/en-us/120877https://support.apple.com/en-us/120879https://support.apple.com/en-us/126632https://support.apple.com/en-us/126646http://seclists.org/fulldisclosure/2026/Mar/1https://access.redhat.com/errata/RHSA-2024:8180https://access.redhat.com/errata/RHSA-2024:8492https://access.redhat.com/errata/RHSA-2024:8496https://access.redhat.com/errata/RHSA-2024:9144https://access.redhat.com/errata/RHSA-2024:9636https://access.redhat.com/errata/RHSA-2024:9646https://access.redhat.com/errata/RHSA-2024:9653https://access.redhat.com/errata/RHSA-2024:9679https://access.redhat.com/errata/RHSA-2024:9680https://access.redhat.com/errata/RHSA-2025:10364https://access.redhat.com/security/cve/CVE-2023-43010https://bugzilla.redhat.com/show_bug.cgi?id=2448778https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-43010.json
2026-03-12
Published