CVE-2023-41993 is a critical WebKit vulnerability affecting Apple products, Debian, Fedora, NetApp, and Oracle, allowing arbitrary code execution through processing malicious web content. With a CVSS score of 8.8 (HIGH), it requires user interaction (UI:R) but can be exploited remotely (AV:N) with low attack complexity (AC:L), leading to high impact on confidentiality, integrity, and availability. This zero-day vulnerability is actively exploited in the wild, particularly against iOS versions prior to 16.7, and has garnered significant community discussion and media coverage, despite a lack of public exploit intelligence tools.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 17.0.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 17.0.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 14.0CPE matchmatch criteria | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.