Apple Releases Security Updates for Multiple Products
The released security updates include an exploited zero-day vulnerability in Safari, macOS Ventura, iOS and iPadOS.
Summary
The released security updates include an exploited zero-day vulnerability in Safari, macOS Ventura, iOS and iPadOS.
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Apple have released six security updates to address vulnerabilities in multiple products. Apple are reporting exploitation of CVE-2023-23529, which impacts Safari, macOS Ventura, iOS and iPadOS. An attacker may exploit some of these vulnerabilities to take control of a vulnerable system.
Exploitation of CVE-2023-23529 in Safari, macOS Ventura, iOS, and iPadOS Products
Apple have reported that this issue may have been actively exploited within Safari, macOS Ventura, iOS, and iPadOS. An attacker could exploit this vulnerability by processing maliciously crafted web content, which could then lead to arbitrary code execution.
Remediation advice
Affected organisations are encouraged to review the following Apple security advisories and apply any relevant updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
iOS 16.3.1 and iPadOS 16.3.1 | HT213635 https://support.apple.com/en-us/HT213635 |
| Patch |
macOS Ventura 13.2.1 | HT213633 https://support.apple.com/en-gb/HT213633 |
| Patch |
Safari 16.3.1 | HT213638 https://support.apple.com/en-gb/HT213638 |
| Guidance |
tvOS 16.3.1 | tvOS 16.3.2 | watchOS 9.3.1 https://support.apple.com/en-gb/HT201222 |
CVE Vulnerabilities
Last edited: 14 February 2023 1:00 pm