CVE-2023-41993 vulnerability in Apple and Other Products
Published on September 21, 2023










Known Exploited Vulnerability
This Apple Multiple Products WebKit Code Execution Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content.
The following remediation steps are recommended / required by October 16, 2023: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Vulnerability Analysis
CVE-2023-41993 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. It has an exploitability score of 2.8 out of four. The potential impact of an exploit of this vulnerability is considered to be very high.
Improper Check for Unusual or Exceptional Conditions
The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.
Products Associated with CVE-2023-41993
You can be notified by stack.watch whenever vulnerabilities like CVE-2023-41993 are published in these products:
What versions are vulnerable to CVE-2023-41993?
-
Apple macOS Fixed in Version 14.0
-
Apple iPadOS Fixed in Version 17.0.1
-
Apple Iphone Os Fixed in Version 17.0.1
-
Fedora Project Fedora Version 37
-
Fedora Project Fedora Version 38
-
Fedora Project Fedora Version 39
-
Debian Linux Version 11.0
-
Debian Linux Version 12.0
-
Oracle Java Development Kit (JDK) Version 1.8.0 update401
-
Oracle Java Runtime Environment (JRE) Version 1.8.0 update401
-
Oracle Graalvm Version 21.3.9
-
Oracle Graalvm Version 20.3.13
-
NetApp Oncommand Workflow Automation Version -
-
NetApp Oncommand Insight Version -
-
NetApp Active Iq Unified Manager Version - windows
-
NetApp Cloud Insights Acquisition Unit Version -
-
NetApp Active Iq Unified Manager Version - vsphere
-
NetApp Cloud Insights Storage Workload Security Agent Version -
-
Webkitgtk Fixed in Version 2.42.2