CVE-2023-43010
Apple Safari vulnerability analysis and mitigation

Overview

CVE-2023-43010 is a memory corruption vulnerability in Apple's WebKit browser engine that allows processing maliciously crafted web content to trigger memory corruption on affected devices. The flaw was originally fixed in iOS 17.2 and iPadOS 17.2 on December 11, 2023, but was publicly disclosed as a CVE on March 11, 2026, when Apple backported the fix to legacy devices unable to upgrade to iOS 17. Affected products include iOS and iPadOS before 15.8.7, 16.7.15, and 17.2; macOS Sonoma before 14.2; and Safari before 17.2. It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation requiring user interaction but no privileges (Apple Advisory iOS 16.7.15, Apple Advisory iOS 17.2, Feedly).

Technical details

The vulnerability is rooted in improper memory handling within WebKit (WebKit Bugzilla: 260913), classified under CWE-120 (Buffer Copy without Checking Size of Input) and CWE-787 (Out-of-bounds Write). An attacker can exploit this by serving maliciously crafted web content — such as a specially constructed webpage — that triggers an out-of-bounds write condition in the WebKit rendering engine when parsed by a vulnerable browser or web view. Exploitation requires user interaction (e.g., visiting a malicious URL) but no authentication or elevated privileges. The fix was addressed with improved memory handling, as noted in Apple's security advisories (Apple Advisory iOS 17.2, Apple Advisory macOS 14.2).

Impact

Successful exploitation can lead to memory corruption on the affected device, with potential consequences including arbitrary code execution, information disclosure, and denial of service. Given that WebKit underpins Safari and all iOS/iPadOS web views, a compromised WebKit process could expose sensitive user data, enable further device compromise, or serve as an entry point for chained exploits targeting kernel-level privileges. The vulnerability affects a broad range of Apple hardware — from legacy iPhone 6s and iPad Air 2 devices to newer models running iOS 17.x and macOS Sonoma — significantly widening the attack surface (Feedly, Apple Advisory iOS 15.8.7).

Exploitation steps

  1. Reconnaissance: Identify target devices running vulnerable iOS/iPadOS versions (below 15.8.7, 16.7.15, or 17.2) or Safari below 17.2, focusing on older hardware (e.g., iPhone 6s–X, iPad 5th gen) that cannot upgrade to the latest iOS.
  2. Craft malicious web content: Develop a specially crafted webpage or web resource that triggers the out-of-bounds write condition in WebKit's memory handling routines (WebKit Bugzilla: 260913).
  3. Deliver payload: Lure the target into visiting the malicious URL via phishing, malvertising, or a compromised website — user interaction (clicking a link or loading a page) is required to trigger the vulnerability.
  4. Trigger memory corruption: When the victim's device processes the crafted web content through Safari or any WebKit-based web view, the buffer overflow/out-of-bounds write is triggered in the WebKit rendering process.
  5. Achieve code execution: Leverage the memory corruption to achieve arbitrary code execution within the WebKit sandbox, potentially chaining with additional exploits (as seen in the Coruna kit, which combined multiple CVEs) to escalate privileges or install persistent malware (Apple Advisory iOS 15.8.7, BleepingComputer).

Indicators of compromise

  • Network: Unusual outbound connections from iOS/macOS devices to unknown or suspicious domains immediately after web browsing activity; traffic patterns consistent with exploit kit infrastructure (e.g., redirects through multiple domains before delivering payload).
  • Logs: Crash reports or WebKit/Safari process crashes (visible in device diagnostic logs) around the time of suspicious web activity; unexpected WebContent process terminations in system logs.
  • Process: Unexpected processes spawned by the WebKit WebContent process; unusual background activity on the device following web browsing sessions.
  • File System: Unexpected configuration profile installations or new applications appearing on the device without user initiation, which may indicate post-exploitation persistence by the Coruna exploit kit.
  • Device Behavior: Unexplained battery drain, increased data usage, or device slowdown following visits to unfamiliar websites, potentially indicating post-exploitation activity (BleepingComputer, SecurityOnline).

Mitigation and workarounds

Apple has released patches addressing CVE-2023-43010 across all affected product lines: iOS 17.2 and iPadOS 17.2 (December 11, 2023), macOS Sonoma 14.2 (December 11, 2023), Safari 17.2 (December 11, 2023), and backported fixes for legacy devices via iOS 15.8.7/iPadOS 15.8.7 and iOS 16.7.15/iPadOS 16.7.15 (both released March 11, 2026). Users should immediately update to the latest available version for their device. For devices that cannot be updated, restricting web browsing to trusted sites and avoiding unknown links can reduce exposure until a patch can be applied (Apple Advisory iOS 15.8.7, Apple Advisory iOS 16.7.15, Apple Advisory macOS 14.2).

Community reactions

The March 2026 disclosure of CVE-2023-43010 generated significant media coverage, primarily focused on Apple's emergency backporting of fixes to legacy devices targeted by the Coruna exploit kit. BleepingComputer, SecurityAffairs, GBHackers, and CyberSecurityNews all covered the story, highlighting the unusual step of Apple issuing security updates for devices as old as the iPhone 6s. The Hacker News also covered related WebKit vulnerability fixes in the same update cycle. Community discussion on Reddit (r/pwnhub, r/CVEWatch) noted the significance of the Coruna exploit kit targeting older, unpatched devices. Security researchers and commentators emphasized the importance of the backported patches for users of legacy hardware who are often overlooked in security update cycles (BleepingComputer, SecurityAffairs, SecurityOnline).

Additional resources


SourceThis report was generated using AI

Related Apple Safari vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64757NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64730NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64728NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64719NONEN/A
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management