First published: Tue Dec 13 2022(Updated: )
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Credit: product-security@apple.com ChengGang Wu Institute of Computing TechnologyYan Kang Institute of Computing TechnologyYuHao Hu Institute of Computing TechnologyYue Sun Institute of Computing TechnologyJiming Wang Institute of Computing TechnologyJiKai Ren Institute of Computing TechnologyHang Shu Institute of Computing TechnologyChinese Academy SciencesYeongHyeon Choi @hyeon101010 Team ApplePIEHyeon Park @tree_segment Team ApplePIESeOk JEON @_seokjeon Team ApplePIEYoungSung Ahn @_ZeroSung Team ApplePIEJunSeo Bae @snakebjs0107 Team ApplePIEDohyun Lee @l33d0hyun Team ApplePIE
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <16.3 | 16.3 |
Apple iOS, iPadOS, and watchOS | <9.3 | 9.3 |
macOS Ventura | <13.2 | 13.2 |
Safari | <16.3 | 16.3 |
Apple iOS and iPadOS | <16.3 | 16.3 |
Apple iOS, iPadOS, and macOS | <16.3 | 16.3 |
Apple iOS and iPadOS | <15.7.2 | 15.7.2 |
Apple iOS, iPadOS, and macOS | <15.7.2 | 15.7.2 |
Safari | <16.3 | |
Apple iOS, iPadOS, and macOS | <16.3 | |
iPhone OS | <16.3 | |
macOS | <13.2 | |
tvOS | <16.3 | |
Apple iOS, iPadOS, and watchOS | <9.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-23496.
The severity level of CVE-2023-23496 is high.
The affected software includes Apple Safari versions up to 16.3, Apple iOS versions up to 15.7.2, and Apple iPadOS versions up to 15.7.2.
To fix CVE-2023-23496, update your software to the fixed versions: macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3.
You can find more information about CVE-2023-23496 on the official Apple support page: [link](https://support.apple.com/en-us/HT213531).