REDHAT-BUG-2185724: Use After Free

Published Apr 11, 2023
·
Updated

CVE-2023-28205 (WebKit)

It is a use-after-free vulnerability that allows attackers to process maliciously crafted web content that may lead to arbitrary code execution.

By tricking targets into loading malicious websites under the control of attackers, it is possible to exploit the vulnerability, which could lead to the execution of malware on compromised systems. Maliciously designed web content can cause the execution of arbitrary code, giving attackers access to your device without your knowledge. Apple has fixed this vulnerability with improved memory management.

WebKit Bugzilla: 254797

https://seclists.org/fulldisclosure/2023/Apr/1 https://seclists.org/fulldisclosure/2023/Apr/2 https://seclists.org/fulldisclosure/2023/Apr/3

Affected Software

1 affected component
Apple WebKit

Event History

Apr 11, 2023
Data Sourced
via Red Hat·05:51 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2185724?

The vulnerability REDHAT-BUG-2185724 is classified as a high severity issue due to its potential for arbitrary code execution.

2

How do I fix REDHAT-BUG-2185724?

To mitigate REDHAT-BUG-2185724, ensure that you update your Apple WebKit to the latest available version.

3

What types of attacks does REDHAT-BUG-2185724 enable?

REDHAT-BUG-2185724 enables attackers to execute arbitrary code by processing maliciously crafted web content.

4

Which software is affected by REDHAT-BUG-2185724?

The affected software for REDHAT-BUG-2185724 is Apple WebKit.

5

What is a use-after-free vulnerability in the context of REDHAT-BUG-2185724?

In REDHAT-BUG-2185724, a use-after-free vulnerability occurs when the program continues to use a memory location after it has been freed, potentially leading to exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203