CVE-2023-32439
Description
Apple iOS, iPadOS, macOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
CISA KEV
- Vendor
- Apple
- Product
- Multiple Products
- Due date
- 2023-07-14
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
CVE-2023-32439 NameCVE-2023-32439 DescriptionA type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. SourceCVE (atβ¦
CVE-2023-32439
| Name | CVE-2023-32439 |
| Description | A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-5449-1 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| webkit2gtk (PTS) | bullseye | 2.44.2-1~deb11u1 | fixed |
| bullseye (security) | 2.50.6-1~deb11u1 | fixed | |
| bookworm, bookworm (security) | 2.50.6-1~deb12u1 | fixed | |
| trixie (security), trixie | 2.52.3-2~deb13u1 | fixed | |
| forky, sid | 2.52.3-2 | fixed | |
| wpewebkit (PTS) | bullseye (security), bullseye | 2.38.6-1~deb11u1 | vulnerable |
| bookworm | 2.38.6-1 | vulnerable | |
| trixie | 2.48.3-1 | fixed | |
| forky | 2.52.3-1 | fixed | |
| sid | 2.52.4-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| webkit2gtk | source | buster | (unfixed) | end-of-life | ||
| webkit2gtk | source | bullseye | 2.40.3-2~deb11u1 | DSA-5449-1 | ||
| webkit2gtk | source | bookworm | 2.40.3-2~deb12u1 | DSA-5449-1 | ||
| webkit2gtk | source | (unstable) | 2.40.3-1 | |||
| wpewebkit | source | (unstable) | 2.40.3-1 |
Notes
[buster] - webkit2gtk <end-of-life> (webkit2gtk EOL in buster)
[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)
[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)
https://webkitgtk.org/security/WSA-2023-0005.html
Apply commands
[buster] - webkit2gtk <end-of-life> (webkit2gtk EOL in buster)[bookworm] - wpewebkit <ignored> (wpewebkit not covered by security support in Bookworm)[bullseye] - wpewebkit <ignored> (wpewebkit >= 2.40 can no longer be sensibly backported)https://webkitgtk.org/security/WSA-2023-0005.html
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 2.40.3-1 |
| sid | Fixed | 2.40.3-1 |
| forky | Fixed | 2.40.3-1 |
| bullseye | Fixed | 2.40.3-2~deb11u1 |
| bookworm | Fixed | 2.40.3-2~deb12u1 |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | β |
| 8 | Fixed | β |
Rocky Linux Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | β |
| 8 | Fixed | β |
References
- https://access.redhat.com/errata/RHSA-2023:4201
- https://errata.rockylinux.org/RLSA-2023:4202
- https://www.suse.com/security/cve/CVE-2023-32439.html
- https://errata.rockylinux.org/RLSA-2023:4201
- https://security-tracker.debian.org/tracker/CVE-2023-32439
- https://support.apple.com/en-us/HT213813, https://support.apple.com/en-us/HT213811, https://support.apple.com/en-us/HT213814, https://support.apple.com/en-us/HT213816; https://nvd.nist.gov/vuln/detail/CVE-2023-32439
- https://access.redhat.com/errata/RHSA-2023:4202
- https://bugzilla.redhat.com/2218626
- https://bugzilla.redhat.com/2218640
- https://errata.almalinux.org/8/ALSA-2023-4202.html
- https://errata.almalinux.org/9/ALSA-2023-4201.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.