First published: Mon Jul 24 2023(Updated: )
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16.6 and iPadOS 16.6, watchOS 9.6, tvOS 16.6, macOS Ventura 13.5. Processing web content may lead to arbitrary code execution.
Credit: product-security@apple.com product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | >=16.0<16.6 | |
Apple iPhone OS | >=16.0<16.6 | |
Apple macOS | >=13.0<13.5 | |
Apple tvOS | <16.6 | |
Apple watchOS | <9.6 | |
ubuntu/webkit2gtk | <2.40.5 | 2.40.5 |
ubuntu/webkit2gtk | <2.40.5-0ubuntu0.22.04.1 | 2.40.5-0ubuntu0.22.04.1 |
ubuntu/webkit2gtk | <2.40.5-0ubuntu0.23.04.1 | 2.40.5-0ubuntu0.23.04.1 |
ubuntu/webkit2gtk | <2.40.5-1 | 2.40.5-1 |
Apple watchOS | <9.6 | 9.6 |
Apple tvOS | <16.6 | 16.6 |
Apple macOS Ventura | <13.5 | 13.5 |
Apple Safari | <16.6 | 16.6 |
debian/webkit2gtk | <=2.36.4-1~deb10u1<=2.38.6-0+deb10u1 | 2.42.2-1~deb11u1 2.42.5-1~deb11u1 2.42.2-1~deb12u1 2.42.5-1~deb12u1 2.42.5-1 |
debian/wpewebkit | <=2.38.6-1~deb11u1<=2.38.6-1 | 2.42.5-1 2.42.5-1.1 |
Apple iOS | <16.6 | 16.6 |
Apple iPadOS | <16.6 | 16.6 |
redhat/webkitgtk | <2.40.5 | 2.40.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-38592.
The severity of CVE-2023-38592 is high (8.8).
The following software versions are affected by CVE-2023-38592: iOS up to 16.6, iPadOS up to 16.6, watchOS up to 9.6, tvOS up to 16.6, and macOS Ventura up to 13.5.
CVE-2023-38592 can lead to arbitrary code execution when processing web content.
To fix CVE-2023-38592, update to the fixed versions provided by Apple: iOS 16.6, iPadOS 16.6, watchOS 9.6, tvOS 16.6, and macOS Ventura 13.5.