Vulnerability record · CVE-2023-32409 · published 23 June 2023
CVE-2023-32409: Apple WebKit bounds check flaw allows Web Content sandbox escape
Apple · Safari
Apple WebKit contained an insufficient bounds check that a remote attacker could use to break out of the Web Content sandbox. Apple stated it was aware of a report that the issue may have been actively exploited, and fixes shipped across watchOS, tvOS, macOS, iOS, iPadOS and Safari. Because the sandbox is the main containment boundary for web content, escaping it exposes the wider device to follow-on compromise.
Description
The issue was addressed with improved bounds checks. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with suspected active exploitation and a high EPSS percentile, but the record gives no confirmed in-the-wild campaign details beyond Apple's statement.
What it is
Apple WebKit contained an insufficient bounds check that a remote attacker could use to break out of the Web Content sandbox. Apple stated it was aware of a report that the issue may have been actively exploited, and fixes shipped across watchOS, tvOS, macOS, iOS, iPadOS and Safari. Because the sandbox is the main containment boundary for web content, escaping it exposes the wider device to follow-on compromise.
Impact
An attacker gains code execution outside the Web Content sandbox, allowing access to resources and data the sandbox is meant to isolate. The CVSS vector rates integrity impact as high with scope change, while confidentiality and availability impacts are recorded as none.
Attack surface
Reachable remotely over the network with no privileges and no user interaction per the CVSS vector (AV:N/AC:L/PR:N/UI:N), consistent with malicious web content processed by WebKit. The record does not describe the specific delivery path beyond web content.
Exploitation
Listed in CISA KEV with a 2023-05-22 addition and 2023-06-12 remediation due date, and Apple stated the issue may have been actively exploited. EPSS gives a 30-day probability of 0.1653 (96.8th percentile). No ransomware campaign use is recorded.
What to do
- Apply the Apple updates that fix this issue: watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.8 and iPadOS 15.7.8, Safari 16.5, iOS 16.5 and iPadOS 16.5.
- Prioritize patching internet-facing and high-value Apple devices first, given KEV listing and suspected active exploitation.
- Track patch compliance for all listed platforms, including older iOS 15.7.8 and iPadOS 15.7.8 branches that remain in use.
- Where immediate patching is not possible, restrict browsing of untrusted web content and reduce exposure of unpatched devices to hostile sites.
- Review vendor advisories HT213757, HT213758, HT213761, HT213762, HT213764 and HT213842 for platform-specific guidance.
Detection
- Monitor for WebKit or WebContent process crashes and abnormal process terminations on Apple endpoints, which can accompany sandbox escape attempts.
- Hunt for unexpected child processes or unusual outbound connections originating from browser or WebContent processes.
- Check endpoint inventories against the fixed OS and Safari versions to find unpatched devices.
- Correlate network or proxy logs for known exploit delivery infrastructure if threat intelligence is available.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-32409 to the Known Exploited Vulnerabilities catalog on 22 May 2023 as "Apple Multiple Products WebKit Sandbox Escape Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 12 June 2023.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT213757 | Vendor Advisory |
| https://support.apple.com/en-us/HT213758 | Vendor Advisory |
| https://support.apple.com/en-us/HT213761 | Vendor Advisory |
| https://support.apple.com/en-us/HT213762 | Vendor Advisory |
| https://support.apple.com/en-us/HT213764 | Vendor Advisory |
| https://support.apple.com/en-us/HT213842 | Vendor Advisory |
| https://support.apple.com/en-us/HT213757 | Vendor Advisory |
| https://support.apple.com/en-us/HT213758 | Vendor Advisory |
| https://support.apple.com/en-us/HT213761 | Vendor Advisory |
| https://support.apple.com/en-us/HT213762 | Vendor Advisory |
| https://support.apple.com/en-us/HT213764 | Vendor Advisory |
| https://support.apple.com/en-us/HT213842 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-32409 | US Government Resource |
Track CVE-2023-32409 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32409), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.