Rewterz

Rewterz Threat Advisory – CVE-2023-28709 – Apache Tomcat Vulnerability

May 23, 2023
Rewterz

Rewterz Threat Advisory – Multiple Apache InLong Vulnerabilities

May 23, 2023

Rewterz Threat Advisory – Multiple Apple Safari, iOS and iPadOS Vulnerabilities

Severity

High

Analysis Summary

CVE-2023-32373 CVSS:8.8

Apple Safari, tvOS, iOS and iPadOS could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the WebKit component. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2023-32409 CVSS:6.5

Apple Safari, iOS and iPadOS could allow a remote attacker to bypass security restrictions, caused by a flaw in the WebKit component. By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to break out of Web Content sandbox.

Impact

  • Code Execution
  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2023-32373
  • CVE-2023-32409

Affected Vendors

Apple

Affected Products

  • Apple Safari 16.4
  • Apple iOS 15.7.5
  • Apple iPadOS 15.7.5
  • Apple iOS 16.4
  • Apple iPadOS 16.4
  • Apple tvOS 16.4

Remediation

Refer to Apple security document for patch, upgrade or suggested workaround information.

Apple iOS 16.5 and Apple iPadOS 16.5

Apple iOS 15.7.6 and Apple iPadOS 15.7.6

Apple Safari 16.5

Apple tvOS 16.5

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.