LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-37450: Apple Multiple Products WebKit Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 13, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-37450 to its Known Exploited Vulnerabilities catalog on Jul 13, 2023, with a federal patch deadline of Aug 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, macOS, and Safari WebKit contain an unspecified vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML…

CVE-2023-37450 is a code-execution vulnerability in WebKit, the engine used by Apple Safari and other HTML parsers. It affects Apple iOS, iPadOS, macOS, and Safari, and can also impact non-Apple products that rely on WebKit for processing web content. When a device processes maliciously crafted web content, an attacker may achieve code execution. This matters because successful exploitation can give an attacker control over the affected process or device, potentially leading to further compromise of user data or systems. Confirm exact impact and scope against the vendor advisory.

CISA directs organizations to apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Known ransomware use is not documented for this CVE.

How it works

The weakness is an unspecified vulnerability in WebKit that results in code execution when the engine processes maliciously crafted web content. WebKit is responsible for parsing and rendering HTML, CSS, JavaScript, and related web resources. An attacker who can deliver such content—typically via a web page or embedded web view—can trigger the flaw during normal content processing.

Because the CWE is not specified in the available record, defenders should treat this as a classic browser/engine memory-safety or parsing issue that allows arbitrary code to run in the context of the WebKit process. The same risk extends to any application that embeds WebKit for HTML handling. Exact exploit mechanics are not detailed publicly in the provided facts; always verify technical details against Apple’s advisory rather than assuming a particular trigger or privilege level.

Am I affected? How to find it in your systems

This vulnerability affects Apple iOS, iPadOS, macOS, and Safari, plus any non-Apple products that use WebKit for HTML processing. Typical locations include:

Inventory steps:

Because exact affected version ranges are not provided here, compare every discovered version against the current Apple security advisory. Log or telemetry signs of exploitation are not detailed in the facts; look for unexpected process crashes in WebKit/Safari, anomalous network connections originating from browser processes, or sudden privilege escalations following web browsing. Correlate with web-proxy or DNS logs for visits to untrusted sites around the time of any suspicious activity.

How to remediate

Patch first. Apply the updates released by Apple for iOS, iPadOS, macOS, and Safari exactly as described in the vendor advisory. For non-Apple products that embed WebKit, obtain and install the corresponding vendor-supplied updates that incorporate the fixed WebKit code. If no update is available for a given product, CISA guidance is to discontinue use of that product.

After patching, harden the environment for this class of browser-engine flaws:

Re-inventory after remediation to confirm every instance has received the vendor update.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If updates remain unavailable indefinitely, plan to discontinue use of the affected product as directed by CISA.

If your data may have been exposed

Code-execution vulnerabilities in web engines can lead to device compromise and subsequent data exposure. Known ransomware use is not documented for CVE-2023-37450. If you suspect exploitation, isolate the device, preserve forensic evidence, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have already appeared in public breach collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
Added to CISA KEVJul 13, 2023
Federal patch deadlineAug 3, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities