First published: Wed Oct 25 2023(Updated: )
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/webkit2gtk | <=2.36.4-1~deb10u1<=2.38.6-0+deb10u1<=2.40.5-1~deb11u1 | 2.42.4-1~deb11u1 2.42.2-1~deb12u1 2.42.4-1~deb12u1 2.42.4-1 |
debian/wpewebkit | <=2.38.6-1~deb11u1<=2.38.6-1 | 2.42.4-1 |
Apple macOS Sonoma | <14.1 | 14.1 |
Apple iOS | <17.1 | 17.1 |
Apple iPadOS | <17.1 | 17.1 |
Apple iOS | <16.7.2 | 16.7.2 |
Apple iPadOS | <16.7.2 | 16.7.2 |
Apple watchOS | <10.1 | 10.1 |
Apple tvOS | <17.1 | 17.1 |
Apple Safari | <17.1 | 17.1 |
Apple Safari | <17.1 | |
Apple iPadOS | <16.7.2 | |
Apple iPadOS | >=17.0<17.1 | |
Apple iPhone OS | <16.7.2 | |
Apple iPhone OS | >=17.0<17.1 | |
Apple macOS | >=14.0<14.1 | |
Apple tvOS | <17.1 | |
Apple watchOS | <10.1 | |
Fedoraproject Fedora | =37 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2023-42852.
A logic issue was addressed with improved checks. Processing web content may lead to arbitrary code execution.
The affected products include macOS Sonoma, Safari, iOS, iPadOS, watchOS, and tvOS.
Versions up to and excluding macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, watchOS 10.1, iOS 17.1 and iPadOS 17.1, tvOS 17.1 are affected by this vulnerability.
To fix this vulnerability, update to iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1.