
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-43010 is a memory corruption vulnerability in Apple's WebKit browser engine that allows processing maliciously crafted web content to trigger memory corruption on affected devices. The flaw was originally fixed in iOS 17.2 and iPadOS 17.2 on December 11, 2023, but was publicly disclosed as a CVE on March 11, 2026, when Apple backported the fix to legacy devices unable to upgrade to iOS 17. Affected products include iOS and iPadOS before 15.8.7, 16.7.15, and 17.2; macOS Sonoma before 14.2; and Safari before 17.2. It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation requiring user interaction but no privileges (Apple Advisory iOS 16.7.15, Apple Advisory iOS 17.2, Feedly).
The vulnerability is rooted in improper memory handling within WebKit (WebKit Bugzilla: 260913), classified under CWE-120 (Buffer Copy without Checking Size of Input) and CWE-787 (Out-of-bounds Write). An attacker can exploit this by serving maliciously crafted web content — such as a specially constructed webpage — that triggers an out-of-bounds write condition in the WebKit rendering engine when parsed by a vulnerable browser or web view. Exploitation requires user interaction (e.g., visiting a malicious URL) but no authentication or elevated privileges. The fix was addressed with improved memory handling, as noted in Apple's security advisories (Apple Advisory iOS 17.2, Apple Advisory macOS 14.2).
Successful exploitation can lead to memory corruption on the affected device, with potential consequences including arbitrary code execution, information disclosure, and denial of service. Given that WebKit underpins Safari and all iOS/iPadOS web views, a compromised WebKit process could expose sensitive user data, enable further device compromise, or serve as an entry point for chained exploits targeting kernel-level privileges. The vulnerability affects a broad range of Apple hardware — from legacy iPhone 6s and iPad Air 2 devices to newer models running iOS 17.x and macOS Sonoma — significantly widening the attack surface (Feedly, Apple Advisory iOS 15.8.7).
Apple has released patches addressing CVE-2023-43010 across all affected product lines: iOS 17.2 and iPadOS 17.2 (December 11, 2023), macOS Sonoma 14.2 (December 11, 2023), Safari 17.2 (December 11, 2023), and backported fixes for legacy devices via iOS 15.8.7/iPadOS 15.8.7 and iOS 16.7.15/iPadOS 16.7.15 (both released March 11, 2026). Users should immediately update to the latest available version for their device. For devices that cannot be updated, restricting web browsing to trusted sites and avoiding unknown links can reduce exposure until a patch can be applied (Apple Advisory iOS 15.8.7, Apple Advisory iOS 16.7.15, Apple Advisory macOS 14.2).
The March 2026 disclosure of CVE-2023-43010 generated significant media coverage, primarily focused on Apple's emergency backporting of fixes to legacy devices targeted by the Coruna exploit kit. BleepingComputer, SecurityAffairs, GBHackers, and CyberSecurityNews all covered the story, highlighting the unusual step of Apple issuing security updates for devices as old as the iPhone 6s. The Hacker News also covered related WebKit vulnerability fixes in the same update cycle. Community discussion on Reddit (r/pwnhub, r/CVEWatch) noted the significance of the Coruna exploit kit targeting older, unpatched devices. Security researchers and commentators emphasized the importance of the backported patches for users of legacy hardware who are often overlooked in security update cycles (BleepingComputer, SecurityAffairs, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."