Vulnerability record · CVE-2023-42917 · published 30 November 2023
CVE-2023-42917: Apple WebKit memory corruption allows code execution via web content
Apple · Safari
CVE-2023-42917 is an out-of-bounds write (CWE-787) in WebKit that Apple addressed with improved locking. Processing malicious web content can lead to arbitrary code execution. Apple states it is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Description
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, CISA KEV listing with known exploitation and a near-term remediation due date, though exploitation requires user interaction.
What it is
CVE-2023-42917 is an out-of-bounds write (CWE-787) in WebKit that Apple addressed with improved locking. Processing malicious web content can lead to arbitrary code execution. Apple states it is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Impact
An attacker who gets a victim to process crafted web content can achieve arbitrary code execution in the context of the affected component, with high impact to confidentiality, integrity and availability.
Attack surface
Reached over the network by processing web content (CVSS vector AV:N/UI:R), so no authentication is required but user interaction is needed to load the malicious content in a browser or WebKit-based app.
Exploitation
CISA added it to KEV on 2023-12-04 with a remediation due date of 2023-12-25, and Apple acknowledged possible exploitation against iOS before 16.7.1; EPSS 30-day probability is 0.0937 (95th percentile).
What to do
- Update to the fixed versions: iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2, and apply the corresponding Debian, Fedora and Gentoo WebKitGTK updates.
- Prioritize patching internet-facing Apple devices and any WebKitGTK-based browsers or applications, given KEV listing and known exploitation.
- If immediate patching is not possible, restrict browsing to trusted sites and reduce exposure of unpatched devices to untrusted web content.
- Track the CISA KEV remediation due date (2023-12-25) and verify all affected endpoints are updated.
Detection
- Monitor for crashes or abnormal process terminations in WebKit-based browsers and apps (Safari, WebKitGTK) that could indicate memory corruption attempts.
- Hunt for suspicious child processes or code execution spawned from browser or WebKit processes on Apple and WebKitGTK systems.
- Review web proxy and DNS logs for access to known exploit or malvertising infrastructure, though the record provides no specific indicators.
- Check endpoint inventory for devices still running iOS, iPadOS, macOS or WebKitGTK versions below the fixed releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-42917 to the Known Exploited Vulnerabilities catalog on 4 December 2023 as "Apple Multiple Products WebKit Memory Corruption Vulnerability". Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 25 December 2023.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-42917 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42917), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.