CVE-2023-41993 vulnerability in Apple and Other Products
Published on September 21, 2023
Known Exploited Vulnerability
This Apple Multiple Products WebKit Code Execution Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that can allow an attacker to execute code when processing web content.
The following remediation steps are recommended / required by October 16, 2023: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Vulnerability Analysis
CVE-2023-41993 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. It has the highest possible exploitability rating (3.9). The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Improper Check for Unusual or Exceptional Conditions
The software does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the software.
Products Associated with CVE-2023-41993
You can be notified by stack.watch whenever vulnerabilities like CVE-2023-41993 are published in these products:
What versions are vulnerable to CVE-2023-41993?
- Apple iOS Version 17.0
- Apple iOS Fixed in Version 16.7
- Apple Macos Fixed in Version 14.0
- Apple Safari Fixed in Version 17.0
- Apple iPad OS Fixed in Version 16.7
- Apple iPad OS Version 17.0
- Fedora Project Fedora Version 37
- Fedora Project Fedora Version 38
- Fedora Project Fedora Version 39
- Debian Linux Version 11.0
- Debian Linux Version 12.0