CVE-2023-43000

9.5 CISA KEV

Apple · macOS, iOS, iPadOS, Safari

A use-after-free vulnerability in multiple Apple products allows attackers to cause memory corruption via maliciously crafted web content.

Executive summary

This critical use-after-free vulnerability in Apple products is currently under active exploitation in the wild and requires immediate patching to prevent potential remote code execution.

Vulnerability

This is a use-after-free memory corruption flaw triggered when an unauthenticated attacker processes maliciously crafted web content. The vulnerability arises from improper memory management, which can lead to system instability or arbitrary code execution.

Business impact

The severity of this vulnerability is rated at 9.5 (Critical) due to its potential for total system impact and confirmed exploitation. Successful exploitation poses a significant risk of unauthorized access, data theft, and loss of system integrity. Organizations relying on these platforms must treat this as a high-priority incident to avoid compromise of sensitive user data and operational continuity.

Remediation

Immediate Action: Update affected devices to macOS Ventura 13.5, iOS 16.6, iPadOS 16.6, Safari 16.6, or iOS/iPadOS 15.8.7 immediately.

Proactive Monitoring: Monitor network traffic for unusual patterns originating from web-browsing sessions and review endpoint logs for unexpected crashes related to memory management.

Compensating Controls: Ensure that advanced threat protection and web content filtering solutions are enabled to block known malicious domains and minimize exposure to untrusted web content.

Exploitation status

Public Exploit Available: Yes.

Analyst recommendation

Due to the confirmed active exploitation and the critical nature of this memory corruption vulnerability, all affected Apple systems must be patched immediately. Delaying these updates exposes the organization to significant risk of exploitation. Please prioritize the deployment of the specified versions across all managed devices without delay.

More Apple CVEs

Sources