apple iphone-os CVE-2023-41993 vulnerability in Apple and Other Products
Published on September 21, 2023

product logo product logo product logo product logo product logo product logo
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Vendor Advisory NVD

Known Exploited Vulnerability

This Apple Multiple Products WebKit Code Execution Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content.

The following remediation steps are recommended / required by October 16, 2023: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vulnerability Analysis

CVE-2023-41993 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.

Improper Check for Unusual or Exceptional Conditions

The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.


Products Associated with CVE-2023-41993

You can be notified by stack.watch whenever vulnerabilities like CVE-2023-41993 are published in these products:

 
 
 
 
 
 
 

What versions are vulnerable to CVE-2023-41993?