Security Alerts

  • Home
  • Security Alerts

WebKit Under Attack: Apple Issues Emergency Patches for 3 New Zero-Day Vulnerabilities

Apple has released security updates for Safari to address a critical vulnerability in WebKit, the open-source web browser engine that powers Safari and other browsers. The vulnerability, tracked as CVE-2023-1987, is a remote code execution (RCE) bug that could allow an attacker to execute arbitrary code on a victim's computer if they visit a malicious website. The vulnerability has been exploited in the wild, and Apple has warned that attackers may be using it to target users of Safari. Apple has released updates for Safari on macOS, iOS, iPadOS, and tvOS. Users are urged to install the updates as soon as possible to protect themselves from this vulnerability. The vulnerability is in the way that WebKit handles certain types of web content. An attacker could exploit the vulnerability by creating a malicious website that contains specially crafted web content. If a victim visits the malicious website, the attacker could then execute arbitrary code on the victim's computer. Apple has not released any details about how the vulnerability was exploited in the wild. However, it is likely that attackers were using it to install malware on victims' computers. Malware can be used to steal personal information, such as passwords and credit card numbers, or to take control of a victim's computer. Users are urged to install the security updates for Safari as soon as possible to protect themselves from this vulnerability. The updates can be installed from the App Store.

Link

https://thehackernews.com/2023/05/webkit-under-attack-apple-issues.html