CVE-2023-37450 is a critical WebKit vulnerability affecting Apple products including iOS, iPadOS, Safari, tvOS, macOS, and watchOS. This high-severity vulnerability (CVSS 8.8) allows for arbitrary code execution simply by processing malicious web content, requiring no user interaction beyond visiting a compromised site. Apple has confirmed active exploitation of this zero-day in the wild, though public exploit code is not readily available. The vulnerability has garnered significant community and media attention, highlighting its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.5.2CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 16.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 16.6CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.5CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
< 16.6CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.