CVE-2023-32359
Rocky Linux vulnerability analysis and mitigation

Overview

CVE-2023-32359 is a security vulnerability discovered in WebKit that affects iOS 16.7.2, iPadOS 16.7.2, and WebKitGTK versions before 2.42.0. The vulnerability was discovered by Claire Houston and was publicly disclosed on October 25, 2023. The issue affects the VoiceOver accessibility feature in WebKit-based systems, where user passwords could potentially be read aloud (Apple Security, WebKit Advisory).

Technical details

The vulnerability stems from insufficient redaction of sensitive information in WebKit's handling of VoiceOver functionality. The issue has been assigned a CVSS v3.1 base score of 7.5 (HIGH), with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating network accessibility with low attack complexity and no required privileges or user interaction (NVD).

Impact

The primary impact of this vulnerability is the potential exposure of sensitive user credentials. When exploited, the vulnerability allows a user's password to be read aloud by the VoiceOver text-to-speech accessibility feature, potentially exposing confidential information to nearby listeners (Apple Security).

Mitigation and workarounds

Apple has addressed this vulnerability by improving the redaction of sensitive information in iOS 16.7.2 and iPadOS 16.7.2. For WebKitGTK users, the fix is available in version 2.42.0 and later. Users are strongly advised to update to these patched versions to protect against potential exploitation (Apple Security, Gentoo Security).

Additional resources


SourceThis report was generated using AI

Related Rocky Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13020HIGH8.8
  • NixOSNixOS
  • firefox
NoYesNov 11, 2025
CVE-2025-59088HIGH8.6
  • Rocky LinuxRocky Linux
  • python3-pyusb
NoYesNov 12, 2025
CVE-2025-13019HIGH8.1
  • NixOSNixOS
  • MozillaFirefox-devel
NoYesNov 11, 2025
CVE-2025-59089MEDIUM5.9
  • Rocky LinuxRocky Linux
  • idm:DL1::ipa-python-compat
NoYesNov 12, 2025
CVE-2025-40185N/AN/A
  • Linux KernelLinux Kernel
  • linux-nvidia-6.11
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management