NA

CVE-2023-28198

Published: 14/08/2023 Updated: 05/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

This vulnerability allows remote malicious users to disclose sensitive information on affected installations of Apple Safari. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the DFG fixup phase. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process.

Vulnerable Product Search on Vulmon Subscribe to Product

apple macos

apple iphone os

apple ipados

wpewebkit wpe webkit

webkitgtk webkitgtk

Vendor Advisories

Synopsis Important: webkit2gtk3 security and bug fix update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this ...
Synopsis Important: webkit2gtk3 security and bug fix update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for webkit2gtk3 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this ...
A use-after-free issue was addressed with improved memory management This issue is fixed in iOS 164 and iPadOS 164, macOS Ventura 133 Processing web content may lead to arbitrary code execution (CVE-2023-28198) A logic issue was addressed with improved validation This issue is fixed in macOS Ventura 133 Content Security Policy to block dom ...
DescriptionThe MITRE CVE dictionary describes this issue as: A use-after-free issue was addressed with improved memory management This issue is fixed in iOS 164 and iPadOS 164, macOS Ventura 133 Processing web content may lead to arbitrary code execution ...