Apple WebKit
cpe:2.3:a:apple:webkit:*:*:*:*:*:*:*
This vulnerability is being actively exploited in the wild.
A vulnerability in WebKit, the engine behind Safari and other Apple applications, allows maliciously crafted web content to break out of the Web Content sandbox. This out-of-bounds write issue could lead to unauthorized actions. The vulnerability has been addressed with improved checks to prevent exploitation. Notably, this issue is a supplementary fix for an attack that was blocked in iOS 17.2. Apple is aware of reports that this vulnerability may have been exploited in a sophisticated attack against targeted individuals on versions of iOS prior to 17.2.
Exploitation of this vulnerability could allow malicious web content to escape the Web Content sandbox, potentially leading to unauthorized actions or access to sensitive information.
Users can update to the latest versions of iOS, iPadOS, macOS Sequoia, Safari, watchOS, and visionOS. Instructions for updating these operating systems are available on the Apple Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.