💻 The vulnerabilities are listed as CVE-2023-32409, CVE-2023-28204, and CVE-2023-32373 and affect WebKit, leading to potential security breaches in web content processing.
🛡️ CVE-2023-32409 allows a malicious actor to break out of the Web Content sandbox and was addressed with improved bounds checks.
📂 CVE-2023-28204 is an out-of-bounds read issue that could disclose sensitive information. It was fixed with improved input validation.
⚙️ CVE-2023-32373 is a use-after free bug that could allow arbitrary code execution. It was resolved with improved memory management.
📰 Both CVE-2023-28204 and CVE-2023-32373 were patched as part of Rapid Security Response updates in iOS 16.4.1 (a) and iPadOS 16.4.1 (a).
https://thehackernews.com/2023/05/webkit-under-attack-apple-issues.html
#tech #technews #technology #infosec #AppleSecurity #ZeroDayVulnerabilities #WebKit #CyberSecurity #RapidSecurityResponse