Lucene search

K
vulnrichmentAppleVULNRICHMENT:CVE-2023-41993
HistorySep 21, 2023 - 6:23 p.m.

CVE-2023-41993

2023-09-2118:23:52
apple
github.com
14
cve-2023-41993
macos sonoma 14
arbitrary code execution
web content
ios 16.7
security issue

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.5%

SSVC

Exploitation

active

Automatable

no

Technical Impact

total

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:o:apple:iphone_os:-:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "iphone_os",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "17.0.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:apple:ipad_os:-:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "ipad_os",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "17.0.1",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*"
    ],
    "vendor": "apple",
    "product": "macos",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "14.0",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*"
    ],
    "vendor": "fedoraproject",
    "product": "fedora",
    "versions": [
      {
        "status": "affected",
        "version": "37"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*"
    ],
    "vendor": "fedoraproject",
    "product": "fedora",
    "versions": [
      {
        "status": "affected",
        "version": "38"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*"
    ],
    "vendor": "fedoraproject",
    "product": "fedora",
    "versions": [
      {
        "status": "affected",
        "version": "39"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
      "cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*"
    ],
    "vendor": "debian",
    "product": "debian_linux",
    "versions": [
      {
        "status": "affected",
        "version": "11.0"
      },
      {
        "status": "affected",
        "version": "12.0"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:oracle:graalvm:21.3.9:*:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "graalvm",
    "versions": [
      {
        "status": "affected",
        "version": "20.3.13"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:oracle:graalvm:21.3.9:*:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "graalvm",
    "versions": [
      {
        "status": "affected",
        "version": "21.3.9"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:oracle:jdk:1.8.0:-:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "jdk",
    "versions": [
      {
        "status": "affected",
        "version": "1.8.0"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:oracle:jre:1.8.0:*:*:*:*:*:*:*"
    ],
    "vendor": "oracle",
    "product": "jre",
    "versions": [
      {
        "status": "affected",
        "version": "1.8.0"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:netapp:cloud_insights_acquisition_unit:-:*:*:*:*:*:*:*"
    ],
    "vendor": "netapp",
    "product": "cloud_insights_acquisition_unit",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:netapp:cloud_insights_storage_workload_security_agent:-:*:*:*:*:*:*:*"
    ],
    "vendor": "netapp",
    "product": "cloud_insights_storage_workload_security_agent",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*"
    ],
    "vendor": "netapp",
    "product": "oncommand_insight",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  },
  {
    "cpes": [
      "cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*"
    ],
    "vendor": "netapp",
    "product": "oncommand_workflow_automation",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "versionType": "custom",
        "lessThanOrEqual": "*"
      }
    ],
    "defaultStatus": "unknown"
  }
]