---
id: CVE-2023-43000
title: A use-after-free issue was addressed with improved memory management
summary: >-
  A use-after-free issue was addressed with improved memory management. This
  issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6,
  iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may
  lead to …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: apple
product: safari
affected:
  - safari < 16.6
  - ipados < 15.8.7
  - 'ipados >= 16.0, < 16.6'
  - iphone_os < 15.8.7
  - 'iphone_os >= 16.0, < 16.6'
  - macos < 13.5
patched:
  - safari 16.6
  - ipados 16.6
  - iphone_os 16.6
  - macos 13.5
published: '2025-11-05'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T18:17:03.620'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-43000'
references:
  - url: 'https://support.apple.com/en-us/120324'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/120331'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/120338'
    label: product-security@apple.com
  - url: 'https://support.apple.com/en-us/126632'
    label: product-security@apple.com
  - url: >-
      https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-43000
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-06T05:01:14.932410Z'
epss: 0.03898
epssPercentile: 0.89875
kev: true
kevDateAdded: '2026-03-05'
kevDueDate: '2026-03-26'
kevRansomware: false
ingestedAt: '2026-09-21T17:49:53.178Z'
---

## Overview

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

## Affected

- `safari < 16.6`
- `ipados < 15.8.7`
- `ipados >= 16.0, < 16.6`
- `iphone_os < 15.8.7`
- `iphone_os >= 16.0, < 16.6`
- `macos < 13.5`

## Remediation

Upgrade past the affected range:

- `safari 16.6`
- `ipados 16.6`
- `iphone_os 16.6`
- `macos 13.5`
