First published: Mon Feb 13 2023(Updated: )
A type confusion issue was addressed with improved checks. This issue is fixed in iOS 15.7.4 and iPadOS 15.7.4, iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Credit: product-security@apple.com product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Multiple Products | ||
Apple Mobile Safari | <16.3 | 16.3 |
Apple iOS, iPadOS, and watchOS | <15.7.4 | 15.7.4 |
Apple iOS, iPadOS, and watchOS | <15.7.4 | 15.7.4 |
Apple iOS, iPadOS, and watchOS | <16.3.1 | 16.3.1 |
Apple iOS, iPadOS, and watchOS | <16.3.1 | 16.3.1 |
Apple Mobile Safari | <16.3 | |
Apple iOS, iPadOS, and watchOS | <15.7.4 | |
Apple iOS, iPadOS, and watchOS | >=16.0<16.3.1 | |
iStyle @cosme iPhone OS | <15.7.4 | |
iStyle @cosme iPhone OS | >=16.0<16.3.1 | |
Apple iOS and macOS | >=13.0<13.2.1 | |
Apple iOS, iPadOS, and watchOS | <16.3.1 | |
iStyle @cosme iPhone OS | <16.3.1 | |
Apple iOS and macOS | <13.2.1 | |
macOS Ventura | <13.2.1 | 13.2.1 |
<16.3 | ||
<15.7.4 | ||
>=16.0<16.3.1 | ||
<15.7.4 | ||
>=16.0<16.3.1 | ||
>=13.0<13.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-23529 is a type confusion vulnerability in Apple Multiple Products, including iOS, iPadOS, and Safari, that could allow arbitrary code execution.
CVE-2023-23529 affects Apple products including iOS, iPadOS, and Safari.
CVE-2023-23529 has a severity rating of 8.8 (high).
To fix CVE-2023-23529, update to the latest available version of iOS, iPadOS, and macOS Ventura, as well as Safari.
You can find more information about CVE-2023-23529 on the Apple support website.