Record summary

CVE-2023-42916 has a selected CVSS score of 6.5 (medium). CISA lists CVE-2023-42916 in KEV.

Description

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Dec 4, 2023 · CISA
VulnCheck KEV
Listed · Nov 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 2, 2023 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Default status: unknown

CVE ListBefore 17.1affected
Before 17.1.2affected
CVE ListBefore 17.1affected

Default status: unknown

CVE ListBefore 14.1affected
14.0.0 to < 14.1.2affected

Default status: unknown

CVE ListBefore 17.1.2affected

Default status: unknown

CVE ListBefore 17.1.2affected

References

Showing 12 of 20