Record summary

CVE-2023-42917 has a selected CVSS score of 8.8 (high). CISA lists CVE-2023-42917 in KEV.

Description

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Dec 4, 2023 · CISA
VulnCheck KEV
Listed · Nov 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 2, 2023 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore 17.1affected
CVE ListBefore 17.1affected
CVE ListBefore 14.1affected

References

Showing 12 of 20