{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-37450",
  "revision": 1,
  "title": "Apple WebKit — code execution from a page",
  "summary": "Processing web content runs the attacker's code. Apple closed it with stricter checks across iOS 16.6, Safari 16.5.2, macOS Ventura 13.5 and the matching tvOS and watchOS builds, and reports active exploitation.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.1895,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-07-13",
    "prerequisites": "The user must open attacker-controlled web content."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "iOS 16.6",
      "Safari 16.5.2",
      "macOS Ventura 13.5",
      "tvOS 16.6",
      "watchOS 9.6"
    ]
  },
  "mitre_attack": [
    "T1203"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update to iOS and iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6 or watchOS 9.6, whichever applies to the device.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-37450",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-37450",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-37450",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37450",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213826"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213841"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213843"
    }
  ],
  "published_at": "2023-07-27T00:15:15.497Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "apple",
    "webkit",
    "safari",
    "ios",
    "code-execution",
    "kev"
  ]
}
