cloud.google.comThird-party advisory
https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit CVE-2023-43000
HIGHCISA KEV
Apple Multiple products Use-After-Free Vulnerability
Record summary
CVE-2023-43000 has a selected CVSS score of 8.8 (high). CISA lists CVE-2023-43000 in KEV.
Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 5, 2026 · CISA
- VulnCheck KEV
- Listed · Mar 3, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 5, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Multiple ProductsBrowse Apple / Multiple Products | CISA | Version data not supplied | |
SafariBrowse Apple / Safari | CVE List | Before 16.6 | affected |
iOS and iPadOSBrowse Apple / iOS and iPadOS | CVE List | Before 16.6 | affected |
| Before 15.8.7 | affected | ||
macOSBrowse Apple / macOS | CVE List | Before 13.5 | affected |
References
7nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-43000 support.apple.com
https://support.apple.com/en-us/120324 support.apple.com
https://support.apple.com/en-us/120331 support.apple.com
https://support.apple.com/en-us/120338 support.apple.com
https://support.apple.com/en-us/126632 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-43000