CVE-2023-32439
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products WebKit Type Confusion Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 24% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-843
מוצרים מושפעים
apple: safari; apple: ipados; apple: iphone os; apple: macos; webkitgtk: webkitgtk\+
קישורים
- https://support.apple.com/en-us/HT213811 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213813 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213814 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213816 Release NotesVendor Advisory
- https://support.apple.com/kb/HT213814 Vendor Advisory
- https://support.apple.com/kb/HT213816 Vendor Advisory
- https://support.apple.com/en-us/HT213811 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213813 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213814 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213816 Release NotesVendor Advisory