First published: Thu May 18 2023(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been actively exploited.
Credit: product-security@apple.com product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | <16.5 | |
Apple iPadOS | <15.7.6 | |
Apple iPadOS | >=16.0<16.5 | |
Apple iPhone OS | <15.7.6 | |
Apple iPhone OS | >=16.0<16.5 | |
Apple macOS | >=13.0<13.4 | |
Apple tvOS | <16.5 | |
Apple watchOS | <9.5 | |
Apple Safari | <16.5 | 16.5 |
Apple iOS | <15.7.6 | 15.7.6 |
Apple iPadOS | <15.7.6 | 15.7.6 |
ubuntu/webkit2gtk | <2.40.2 | 2.40.2 |
ubuntu/webkit2gtk | <2.40.4-0ubuntu0.23.04.1 | 2.40.4-0ubuntu0.23.04.1 |
ubuntu/webkit2gtk | <2.40.4-0ubuntu0.22.04.1 | 2.40.4-0ubuntu0.22.04.1 |
debian/webkit2gtk | <=2.36.4-1~deb10u1<=2.38.6-0+deb10u1 | 2.42.2-1~deb11u1 2.42.5-1~deb11u1 2.42.2-1~deb12u1 2.42.5-1~deb12u1 2.42.5-1 |
debian/wpewebkit | <=2.38.6-1~deb11u1<=2.38.6-1 | 2.42.5-1 2.42.5-1.1 |
Apple iOS | <16.5 | 16.5 |
Apple iPadOS | <16.5 | 16.5 |
Apple watchOS | <9.5 | 9.5 |
Apple tvOS | <16.5 | 16.5 |
Apple Multiple Products | ||
Webkitgtk Webkitgtk\+ | <2.42.3 | |
Apple macOS | <13.4 | 13.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-28204.
The severity level of CVE-2023-28204 is medium.
CVE-2023-28204 affects Apple Multiple Products, iOS, iPadOS, Safari, macOS Ventura, tvOS, and watchOS.
To fix CVE-2023-28204, update to the latest versions of watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, and Safari 16.5.
You can find more information about CVE-2023-28204 on the Apple support website: [link](https://support.apple.com/en-us/HT213757).