CVE-2023-42916

Red Hat Security Advisory: webkitgtk4 security update

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2023-42916 is a network-reachable, zero-click-on-the-user-side vulnerability (AV:N, AC:L, PR:N, UI:R) that requires only a single page visit to a malicious or compromised website to leak sensitive memory contents — potentially session tokens, key material, or cached credentials — to the attacker. The EPSS score at the 97th percentile places it among the most likely-to-be-exploited CVEs across the entire NVD corpus, and Apple's own advisory confirms active exploitation against pre-16.7.1 iOS versions, a strong indicator of targeted campaigns against high-value individuals. The CVSS base score of 6.5 understates operational risk because it reflects only confidentiality impact — the absence of integrity and availability components lowers the score, not the real-world damage potential of credential theft. For NIS2-scoped organisations with BYOD policies or corporate-issued Apple devices accessing internal portals, the risk of browser-context data exfiltration warrants treating this as a high-priority patch obligation regardless of the moderate CVSS rating. No ransomware campaign use has been flagged by CISA, but targeted information-theft scenarios remain a credible threat.

Runbook · Step 1

Immediate response (0-24 h)

  • iOS/iPadOS: Push iOS 17.1.2 / iPadOS 17.1.2 immediately via Settings → General → Software Update. Devices running iOS 15.x or any 16.x release prior to 16.7.1 have confirmed exploitation history — treat these as highest priority.
  • macOS: Deploy macOS Sonoma 14.1.2. Devices that cannot run Sonoma will not receive a patch for this vulnerability — activate compensating controls immediately (see Mitigation layers).
  • Safari (standalone): Deliver Safari 17.1.2 to macOS Ventura and Monterey endpoints via System Settings → Software Update or your software-distribution toolchain.
  • MDM compliance sweep: Query all managed Apple devices in your MDM (Jamf, Microsoft Intune, etc.) for patch compliance; move non-compliant devices into a restricted policy or disconnect them from corporate network resources until patched.
  • Identify embedded WebKit consumers: Audit internal and third-party applications that embed WebKit as an HTML rendering engine (e.g. Electron apps on macOS, hybrid mobile apps) and check vendor advisories for each.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Move unpatched Apple devices into an isolated VLAN with no access to internal resources (SharePoint, VPN gateways, internal APIs) until the patch is applied.
  • Web proxy / DNS filtering: Block known malvertising and drive-by domains at the central web proxy (Zscaler, Cisco Umbrella, etc.); enforce category blocks for "Newly Registered Domains" and "Uncategorized" for unpatched endpoints.
  • Restrict Safari usage: Via MDM configuration profile, disable JavaScript in Safari or enforce an alternative default browser where technically feasible. Note: on iOS/iPadOS all third-party browsers also use WebKit — browser substitution does not eliminate the attack surface on mobile.
  • Managed-app compliance gate: Use MDM conditional-access policies to block access to sensitive enterprise apps (corporate email, VPN client) on any device that does not meet the minimum OS version requirement.
  • IPS signatures: Check your Snort/Suricata ruleset provider (e.g. Emerging Threats) for CVE-2023-42916 signatures and deploy them on perimeter and internal IPS sensors.

Runbook · Step 3

Detection rules

  • Proxy / DNS logs: Unusual requests from Apple User-Agent strings (e.g. Mobile/15E148 Safari/604.1) to newly registered or low-reputation domains, especially immediately before or after access to internal resources — SPL: index=proxy useragent="*Safari*" (category="newly_registered" OR reputation_score<20) | stats count by src_ip, dest_domain.
  • EDR telemetry (macOS): Process ancestry chains where com.apple.WebKit.WebContent or SafariServices spawns unexpected child processes such as shells, curl, or osascript — Sigma shape: ParentImage|endswith: 'com.apple.WebKit.WebContent' AND Image|endswith: ('/bin/sh', '/usr/bin/curl', 'osascript').
  • Unified Log / crash reports: A spike in ReportCrash entries for WebKit processes on a single device can indicate repeated exploitation attempts that have not yet succeeded reliably — collect via MDM log-forwarding or Endpoint Security framework.
  • Network telemetry (Zeek): Monitor http.log for responses with malformed or anomalously large HTML payloads delivered to Safari User-Agent strings; alert on response_body_len outliers combined with resp_mime_types: text/html.
  • MDM compliance alert: Configure an automated high-severity alert for any device reporting an OS version below 17.1.2 (or below 16.7.1 for the legacy branch) after the CISA KEV deadline of 2023-12-04 — escalate directly into your SIEM or ticketing workflow.

Metrics

Severity
critical
Actively exploited
actively exploited (KEV)
6.5
Source: nvd-v3
97.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
17.8 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2025-07-07 02:28 UTC

Affected operating systems

  • linux

    debian / debian_linux10.0

  • linux

    debian / debian_linux11.0

  • linux

    debian / debian_linux12.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • macos

    apple / mac_os_x10.14.6

  • macos

    apple / mac_os_x10.15.7

  • macos

    apple / mac_os_x

  • macos

    apple / macos

  • macos

    apple / visionos

  • mobile

    apple / iphone_os

  • other

    fedoraproject / fedora32

  • other

    fedoraproject / fedora33

  • other

    fedoraproject / fedora35

  • other

    fedoraproject / fedora36

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

  • other

    fedoraproject / fedora39

  • other

    fedoraproject / fedora40

  • other

    apple / ipados

  • other

    apple / tvos

  • other

    apple / watchos

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • apple

    safari14.1

  • apple

    safari14.1.1

  • apple

    safari15.3

  • apple

    safari15.6

  • apple

    safari15.6.1

  • apple

    safari16.0

  • apple

    safari16.2

  • apple

    safari16.3

  • apple

    safari16.4

  • apple

    safari16.4.1

  • apple

    safari16.5

  • apple

    safari16.5.1

  • apple

    safari16.5.2

  • apple

    safari17.0

  • apple

    safari17.1.2

  • apple

    safari17.2

  • apple

    safari17.6

  • apple

    safari18.0

  • apple

    safari18.2

  • apple

    safari18.4

  • bitnami

    jre1.9.0

  • google

    chrome124.0.6367.155

  • google

    chrome35.0.1916.113

  • google

    chrome

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Linked CVEs

Show 205 more CVEs
IDCVE-2023-42916