CVE-2023-32409
Apple Multiple Products WebKit Sandbox Escape Vulnerability
8.6
HIGH
CVSS 3.1
⚠ KEVEPSS 0.30%
Description
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.
How to fix CVE-2023-32409
To remediate CVE-2023-32409, upgrade the affected package to a fixed version below.
- —upgrade to 2.42.0-1 or later
- —no fix listed
Is CVE-2023-32409 being exploited?
Yes — CVE-2023-32409 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (2)
- from 0, < 2.42.0-1
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |