CVE-2023-28205 is a critical use-after-free vulnerability affecting Apple Safari, iOS, iPadOS, and macOS, allowing arbitrary code execution through maliciously crafted web content. With a CVSS score of 8.8 (High), it presents a significant risk as it can be exploited remotely with low attack complexity, leading to full compromise of confidentiality, integrity, and availability. Apple has confirmed active exploitation of this zero-day vulnerability, necessitating immediate patching, as evidenced by its inclusion in the KEV catalog and high community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.4.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 15.7.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.4.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 15.7.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 16.0, < 16.4.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.