CVE-2023-41993

HIGH KEV

Apple Macos < 14.0 - Improper Condition Check

Title source: rule

Description

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Exploits (5)

nomisec WORKING POC 200 stars
by po6ix · client-side
https://github.com/po6ix/POC-for-CVE-2023-41993
nomisec WORKING POC 16 stars
by hrtowii · client-side
https://github.com/hrtowii/cve-2023-41993-test
nomisec WORKING POC 5 stars
by 0x06060606 · client-side
https://github.com/0x06060606/CVE-2023-41993
nomisec STUB
by J3Ss0u · client-side
https://github.com/J3Ss0u/CVE-2023-41993

Scores

CVSS v3 8.8
EPSS 0.2441
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-09-25
VulnCheck KEV 2023-09-12
InTheWild.io 2023-09-12
ENISA EUVD EUVD-2023-46452
CWE
CWE-754
Status published
Products (18)
apple/ipados < 17.0.1
apple/iphone_os < 17.0.1
apple/macos < 14.0
debian/debian_linux 11.0
debian/debian_linux 12.0
fedoraproject/fedora 37
fedoraproject/fedora 38
fedoraproject/fedora 39
netapp/active_iq_unified_manager (2 CPE variants)
netapp/cloud_insights_acquisition_unit
... and 8 more
Published Sep 21, 2023
KEV Added Sep 25, 2023
Tracked Since Feb 18, 2026