Rewterz
Rewterz Threat Advisory – Multiple VMware Tools Vulnerabilities
October 27, 2023
Rewterz
Rewterz Threat Advisory – Multiple Apple watchOS Vulnerabilities
October 27, 2023

Rewterz Threat Advisory – Multiple Apple Safari Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-40447 CVSS:8.8

Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by an error in the WebKit component. By persuading a victim to visit a specially crafted web site, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-41976 CVSS:8.8

Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free in the WebKit component. By persuading a victim to visit a specially crafted web site, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-42852 CVSS:8.8

Apple Safari could allow a remote attacker to execute arbitrary code on the system, caused by a logic issue in the WebKit component. By persuading a victim to visit a specially crafted web site, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-41983 CVSS:6.5

Apple Safari is vulnerable to a denial of service, caused by an error in the WebKit component. By persuading a victim to visit a specially crafted web site, an attacker could exploit this vulnerability to cause a denial of service.

Impact

  • Denial of Service
  • Code Execution
  • Gain Access

Indicators Of Compromise

CVE

  • CVE-2023-40447
  • CVE-2023-41976
  • CVE-2023-42852
  • CVE-2023-41983

Affected Vendors

Apple

Affected Products

  • Apple Safari 17.0

Remediation

Refer to Apple Security Advisory for patch, upgrade or suggested workaround information.

Apple Security Advisory