NVD disclosure day

Published threat advisories for June 23, 2023

CVE advisoryKnown Exploit

CVE-2023-32439

Apple Software Vulnerability Allows Code Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A type confusion vulnerability in Apple software could allow attackers to execute arbitrary code by processing malicious web content. Apple is aware of reports that this issue may have been actively exploited, posing a risk to affected organizations and their data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-32435

Apple WebKit Memory Corruption Vulnerability Affects Multiple Products

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A memory corruption flaw in Apple products allows arbitrary code execution when processing web content. This impacts organizations using affected Apple devices and software. Business risk includes potential unauthorized code execution.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-32434

Apple Operating Systems Vulnerability Allows Kernel Privilege Escalation

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An integer overflow vulnerability in Apple operating systems could allow an application to execute arbitrary code with kernel privileges. This impacts iOS, iPadOS, macOS, and watchOS devices. The risk to organizations includes potential device compromise and unauthorized access to data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-32409

Apple Software Sandbox Escape Vulnerability Advisory

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in Apple's WebKit allows remote attackers to bypass security restrictions, potentially affecting multiple Apple products and Safari. This could lead to unauthorized access and data compromise. Affected organizations should apply available updates to mitigate risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-32373

Apple Products Web Content Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A memory management vulnerability in Apple products may allow attackers to execute arbitrary code by processing malicious web content. This could impact affected organizations by compromising systems and data. Applying vendor updates is recommended to mitigate business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-28204

Apple Products Information Disclosure Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Apple's WebKit framework may allow attackers to disclose sensitive information. This affects various Apple products and applications that rely on WebKit for processing web content. Active exploitation has been reported, posing a risk of data exposure for affected organizations.

• CISA KEV