{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-32409",
  "revision": 1,
  "title": "Apple WebKit — out of the web content isolation",
  "summary": "A remote attacker breaks out of the isolation Apple puts around web content, which Apple addressed with better bounds checks. Active exploitation was reported, and the fix spans every platform that ships the engine.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.6,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N",
    "version": "3.1"
  },
  "epss": 0.1653,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-05-22",
    "prerequisites": "The user must open attacker-controlled web content."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "iOS 16.5",
      "iOS 15.7.8",
      "macOS Ventura 13.4",
      "Safari 16.5",
      "tvOS 16.5",
      "watchOS 9.5"
    ]
  },
  "mitre_attack": [
    "T1203"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update to iOS and iPadOS 16.5 or 15.7.8, macOS Ventura 13.4, Safari 16.5, tvOS 16.5 or watchOS 9.5, whichever applies.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-32409",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-32409",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-32409",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32409",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213757"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213758"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213761"
    }
  ],
  "published_at": "2023-06-23T18:15:13.183Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "apple",
    "webkit",
    "safari",
    "sandbox-escape",
    "kev"
  ]
}
