CVE-2023-32373 Details
Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
A use-after-free vulnerability has been identified in the WebKit component of multiple Apple products, including iOS, iPadOS, macOS, tvOS, watchOS, and Safari. This vulnerability arises from improper memory management, which can be exploited by processing maliciously crafted web content, potentially leading to arbitrary code execution. The issue has been addressed in the latest versions of these operating systems and applications.
Users can upgrade to the latest version of the operating system or application where this vulnerability has been fixed. Specific update instructions can be found on the Apple Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Apple Multiple Products WebKit Use-After-Free Vulnerability | May 22, 2023 | Jun 12, 2023 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
| CWE-416 | Use After Free | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apple safari | < 16.5 |
CPE
Remediation
| |
| apple ipados | < 15.7.6 >= 16.0, < 16.5 |
CPE
Remediation
| |
| apple iphone os | >= 15.0, < 15.7.6 >= 16.0, < 16.5 |
CPE
Remediation
| |
| apple macos | < 13.4 |
CPE
Remediation
| |
| apple tvos | < 16.5 |
CPE
Remediation
| |
| apple watchos | < 9.5 |
CPE
Remediation
| |
| redhat enterprise linux | 6.0 7.0 8.0 9.0 |
CPE
Remediation
| |
| webkitgtk webkitgtk+ | < 2.42.3 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 28, 2025 | Modified Analysis | [email protected] |
| Feb 3, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 27, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 5, 2024 | CVE Modified | [email protected] |
| Aug 29, 2023 | Modified Analysis | [email protected] |
| Jul 27, 2023 | CVE Modified | [email protected] |
| Jul 27, 2023 | CVE Modified | [email protected] |
| Jun 27, 2023 | Initial Analysis | [email protected] |