Vulnerability intelligence
CVE-2023-43000
Apple Multiple products Use-After-Free Vulnerability
Apple Multiple Products
Apple macOS, iOS, iPadOS, and Safari 16.6 contain a use-after-free vulnerability due to the processing of maliciously crafted web content that may lead to memory corruption.
CVSS Score
—
Unrated
EPSS — Exploit Probability
3.9%
Riskier than 90% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
KEV since 2026-03-05
Remediation
Unconfirmed
Federal deadline 2026-03-26
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-03-26.
10 articles across 7 outlets · first covered Mar 4, 2026 · latest Mar 12, 2026
Coverage timeline
-
Apple patches Coruna exploit kit flaws for older iOS versionswww.malwarebytes.com · Mar 12, 2026
-
Apple issues emergency fixes for Coruna flaws in older iOS versionssecurityaffairs.com · Mar 12, 2026
-
Apple Updates Older iOS Versions to Patch Coruna Exploitswww.securityweek.com · Mar 12, 2026
-
Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploitthehackernews.com · Mar 12, 2026
-
CISA orders patch after Coruna kit exploits three iOS CVEsarstechnica.com · Mar 6, 2026
-
CISA Adds Coruna iOS Exploit Kit Flaws to the KEV List, 12 CVEswww.securityweek.com · Mar 6, 2026
-
CISA Adds CVEs to KEV for Apple Rockwell and Hikvision Flawssecurityaffairs.com · Mar 6, 2026
-
CVE-2023-43000 Use-After-Free flaw hits Apple Safari on macOS iOSwww.cisa.gov · Mar 5, 2026
-
Apple CVE-2023-43000 Use-After-Free Active Exploitation Patch Nowcisa.gov · Mar 5, 2026
-
Coruna iOS Exploit Kit uses 23 exploits including CVE-2024-23222thehackernews.com · Mar 4, 2026