First published: Mon Feb 13 2023(Updated: )
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Credit: product-security@apple.com product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <16.3 | 16.3 |
Apple macOS Ventura | <13.2.1 | 13.2.1 |
Apple iOS | <15.7.4 | 15.7.4 |
Apple iPadOS | <15.7.4 | 15.7.4 |
Apple iOS | <16.3.1 | 16.3.1 |
Apple iPadOS | <16.3.1 | 16.3.1 |
Apple Safari | <16.3 | |
Apple iPadOS | <16.3.1 | |
Apple iPhone OS | <16.3.1 | |
Apple macOS | <13.2.1 | |
Apple Multiple Products | ||
Apple iPadOS | <15.7.4 | |
Apple iPadOS | >=16.0<16.3.1 | |
Apple iPhone OS | <15.7.4 | |
Apple iPhone OS | >=16.0<16.3.1 | |
Apple macOS | >=13.0<13.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-23529 is a type confusion vulnerability in Apple Multiple Products, including iOS, iPadOS, and Safari, that could allow arbitrary code execution.
CVE-2023-23529 affects Apple products including iOS, iPadOS, and Safari.
CVE-2023-23529 has a severity rating of 8.8 (high).
To fix CVE-2023-23529, update to the latest available version of iOS, iPadOS, and macOS Ventura, as well as Safari.
You can find more information about CVE-2023-23529 on the Apple support website.