Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Jun 12, 2023

CVE-2023-32409

High
EPSS 0.3%CISA KEV
Apple/Multiple Products

Description

Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out of the Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

EPSS — Exploit Probability

0.3%

Higher than 48.0% of all CVEs

Required Action

https://support.apple.com/HT213757, https://support.apple.com/HT213758, https://support.apple.com/HT213761, https://support.apple.com/HT213762, https://support.apple.com/HT213764, https://support.apple.com/HT213765; https://nvd.nist.gov/vuln/detail/CVE-2023-32409

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
0.3%
CISA KEV
Yes
Ransomware
Unknown
Articles
1

Timeline

Published

May 22, 2023

Added to KEV

May 22, 2023

Remediation Due

Jun 12, 2023

Affected Product

Apple

Multiple Products

View all Apple CVEs