CVE-2023-42916
בינונית 6.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
תיאור (מקור, אנגלית)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 18% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-125
מוצרים מושפעים
apple: safari; apple: ipados; apple: iphone os; apple: macos; fedoraproject: fedora; debian: debian linux; webkitgtk: webkitgtk\+
קישורים
- https://support.apple.com/en-us/HT214031 Vendor Advisory
- https://support.apple.com/en-us/HT214032 Vendor Advisory
- https://support.apple.com/en-us/HT214033 Vendor Advisory
- https://support.apple.com/kb/HT214033 Vendor Advisory
- https://support.apple.com/kb/HT214034 Vendor Advisory
- https://support.apple.com/kb/HT214062 Vendor Advisory
- https://support.apple.com/en-us/HT214031 Vendor Advisory
- https://support.apple.com/en-us/HT214032 Vendor Advisory
- https://support.apple.com/en-us/HT214033 Vendor Advisory
- https://support.apple.com/kb/HT214033 Vendor Advisory