nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-32402 CVE-2023-32402
MEDIUM
Apple safari Out-of-bounds Read
Record summary
CVE-2023-32402 has a selected CVSS score of 6.5 (medium).
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, Safari 16.5, iOS 16.5 and iPadOS 16.5. Processing web content may disclose sensitive information.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 18, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 5, 2024 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
SafariBrowse Apple / Safari | CVE List, VulnCheck | Before 16.5 | affected |
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 16.5 | affected |
macOSBrowse Apple / macOS | CVE List | Before 13.4 | affected |
| CVE List | Before 16.5 | affected | |
watchOSBrowse Apple / watchOS | CVE List | Before 9.5 | affected |
References
6support.apple.com
https://support.apple.com/en-us/HT213757 support.apple.com
https://support.apple.com/en-us/HT213758 support.apple.com
https://support.apple.com/en-us/HT213761 support.apple.com
https://support.apple.com/en-us/HT213762 support.apple.com
https://support.apple.com/en-us/HT213764