CVE-2023-28205:Use-after-free vulnerability in WebKit allows arbitrary code execution when processing malicious web content.

splash
Back

Description Preview

CVE-2023-28205 is a use-after-free vulnerability in Apple's WebKit browser engine that affects Safari and iOS/iPadOS devices. The vulnerability occurs due to improper memory management, allowing attackers to execute arbitrary code by processing specially crafted web content. This vulnerability has been actively exploited in the wild according to Apple. The issue affects multiple Apple operating systems including iOS, iPadOS, and macOS.

Overview

This vulnerability (CWE-416: Use After Free) in WebKit allows attackers to execute arbitrary code on affected systems by tricking users into visiting maliciously crafted web pages. When WebKit processes the malicious content, it can access memory after it has been freed, leading to potential code execution with the privileges of the WebKit process. Apple has acknowledged that this vulnerability has been actively exploited, making it a zero-day vulnerability that poses significant risk to users of affected devices. The vulnerability impacts Safari browser and WebKit implementations across multiple Apple operating systems.

Remediation

Users should immediately update their Apple devices to the following versions which contain fixes for this vulnerability:

  • Safari 16.4.1
  • iOS 15.7.5 and iPadOS 15.7.5
  • iOS 16.4.1 and iPadOS 16.4.1
  • macOS Ventura 13.3.1

To update:

  1. For iOS/iPadOS devices: Go to Settings > General > Software Update
  2. For macOS: Go to System Preferences > Software Update
  3. For Safari: Update through the App Store or as part of an OS update

Until updates can be applied, users should minimize browsing untrusted websites and consider using alternative browsers if necessary, although this is not a complete mitigation as WebKit is used by all browsers on iOS/iPadOS.

References

  1. Apple Security Updates - iOS 15.7.5 and iPadOS 15.7.5: https://support.apple.com/en-us/HT213720
  2. Apple Security Updates - iOS 16.4.1 and iPadOS 16.4.1: https://support.apple.com/en-us/HT213721
  3. Apple Security Updates - macOS Ventura 13.3.1: https://support.apple.com/en-us/HT213722
  4. Apple Security Updates - Safari 16.4.1: https://support.apple.com/en-us/HT213723
  5. CWE-416: Use After Free: https://cwe.mitre.org/data/definitions/416.html

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Health Care & Social Assistance
    Health Care & Social Assistance
  2. Manufacturing
    Manufacturing
  3. Public Administration
    Public Administration
  4. Educational Services
    Educational Services
  5. Finance and Insurance
    Finance and Insurance
  6. Retail Trade
    Retail Trade
  7. Transportation & Warehousing
    Transportation & Warehousing
  8. Other Services (except Public Administration)
    Other Services (except Public Administration)
  9. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  10. Utilities
    Utilities
  11. Information
    Information
  12. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  13. Management of Companies & Enterprises
    Management of Companies & Enterprises
  14. Accommodation & Food Services
    Accommodation & Food Services
  15. Mining
    Mining
  16. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  17. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  18. Construction
    Construction
  19. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background
Armis Vulnerability Intelligence Database