CVE-2023-41993: Apple Multiple Products WebKit Code Execution Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2023-09-25. EPSS: 24.3% chance of exploitation in the next 30 days.

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Affected products

  • Apple iPadOS: before 17.0.1 (fixed in 17.0.1)
  • Apple iPhone OS: before 17.0.1 (fixed in 17.0.1)
  • Apple macOS: before 14.0 (fixed in 14.0)
  • Debian Debian Linux: version 11.0 only; version 12.0 only
  • Fedoraproject Fedora: version 37 only; version 38 only; version 39 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Cloud Insights Acquisition Unit: affected versions not specified
  • Netapp Cloud Insights Storage Workload Security Agent: affected versions not specified
  • Netapp Oncommand Insight: affected versions not specified
  • Netapp Oncommand Workflow Automation: affected versions not specified
  • Oracle Graalvm: version 20.3.13 only; version 21.3.9 only
  • Oracle JDK: version 1.8.0 only
  • Oracle JRE: version 1.8.0 only
  • WebKitGTK Webkitgtk+: before 2.42.2 (fixed in 2.42.2)

Published 2023-09-21. Last modified 2026-06-17.