peter bassill · operator
$ cve CVE-2023-43000 JSON

CVE-2023-43000 KEV

8.8
HIGH · CVSS 3.1 · EPSS 3.9% (pctl 90)

Patch first

On CISA KEV — known exploited in the wild, due 2026-03-26.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS3.9% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2026-03-26
Public exploitnone known
Published2025-11-05
Last modified2026-09-21

CISA KEV

NameApple Multiple products Use-After-Free Vulnerability
Added2026-03-05
Due2026-03-26
Vendor / productApple / Multiple Products
Ransomware usenone reported

Affected (4)

VendorProduct
appleipados
appleiphone os
applemacos
applesafari

References

→ the Explorer  ·  watch your stack  ·  NVD