
PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability
This vulnerability affects Apple WebKit and can be exploited through maliciously crafted web content, potentially allowing arbitrary code execution in the context of the WebKit process.
The affected WebKit build analyzed in this repository is based on WebKit-613.1.17.1 (PlayStation / Safari 15.4 lineage).
The proof of concept triggers a use-after-free (UAF) condition by
intentionally delaying the registration of JavaScript objects such as
Map and Date during structured cloning operations.
This timing window allows the JavaScriptCore Garbage Collector (GC) to reclaim objects that are still logically in use, resulting in stale pointers being dereferenced during continued execution.
SerializedScriptValueCloneDeserializer::deserialize()The vulnerability resides in the structured clone deserialization logic, specifically in how newly created JavaScript objects are tracked during recursive deserialization.
In SerializedScriptValue.cpp, the deserializer uses standard WebKit
containers such as:
Vector<JSObject*, 32> outputObjectStack;
Vector<JSMap*, 4> mapStack;
Vector<JSSet*, 4> setStack;
These Vector containers are not scanned by the Garbage Collector.
If a garbage collection cycle is triggered during deserialization
(for example via memory pressure or re-entrant JS execution), objects
referenced only by these containers may be incorrectly collected.
The deserializer, however, continues to use these dangling pointers, resulting in a use-after-free condition.
The official WebKit security patch (commit c9880de) replaces these
containers with MarkedVector, a GC-aware structure that properly
registers its contents as GC roots.
In the analyzed build:
MarkedVector is not implementedCloneDeserializer still uses VectorThis confirms that the build is fully vulnerable to CVE-2023-28205.
The following crash was reliably triggered by the PoC and is consistent with a post-GC stale pointer dereference.
SIGSEGV (11)0x0000000000000068SceNKWebProcesslibSceNKWebKit.sprxThe fault address 0x68 indicates a NULL base pointer dereference with
an object-field offset, a classic signature of accessing a freed
JavaScript object.
Register state confirms:
RAX = 0x0 (NULL object base)This crash behavior is a direct manifestation of the
CloneDeserializer UAF described above.