← All CVEs

CVE-2023-41993

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2023-09-25Remediation due 2023-10-16

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

8.8
CVSS
29.2%
EPSS (exploit prob.)
98th
EPSS percentile
2023-09-21
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-754

Affected products

VendorProductAffected versions
appleipados< 17.0.1
appleiphone_os< 17.0.1
applemacos< 14.0
fedoraprojectfedora37
fedoraprojectfedora38
fedoraprojectfedora39
debiandebian_linux11.0
debiandebian_linux12.0
oraclegraalvm20.3.13
oraclegraalvm21.3.9
oraclejdk1.8.0
oraclejre1.8.0
netappactive_iq_unified_managerall versions
netappactive_iq_unified_managerall versions
netappcloud_insights_acquisition_unitall versions
netappcloud_insights_storage_workload_security_agentall versions
netapponcommand_insightall versions
netapponcommand_workflow_automationall versions
webkitgtkwebkitgtk+< 2.42.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-41993