Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/seregonwar/uaf-2023-28205
Vulnerability AnalysisExploitationWeb Application ExploitationLearning & EducationPayload DevelopmentBinary Exploitation
GitHubseregonwar/uaf-2023-28205

uaf-2023-28205

PoC CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability

View Repository
8148 months agoNot yet reviewed
Website

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-28205: Apple WebKit Use-After-Free Vulnerability

This vulnerability affects Apple WebKit and can be exploited through maliciously crafted web content, potentially allowing arbitrary code execution in the context of the WebKit process.

The affected WebKit build analyzed in this repository is based on WebKit-613.1.17.1 (PlayStation / Safari 15.4 lineage).


Description

The proof of concept triggers a use-after-free (UAF) condition by intentionally delaying the registration of JavaScript objects such as Map and Date during structured cloning operations.

This timing window allows the JavaScriptCore Garbage Collector (GC) to reclaim objects that are still logically in use, resulting in stale pointers being dereferenced during continued execution.


Technical Root Cause (CVE-2023-28205)

Affected Component

  • SerializedScriptValue
  • CloneDeserializer::deserialize()

Root Cause

The vulnerability resides in the structured clone deserialization logic, specifically in how newly created JavaScript objects are tracked during recursive deserialization.

In SerializedScriptValue.cpp, the deserializer uses standard WebKit containers such as:

Vector<JSObject*, 32> outputObjectStack;
Vector<JSMap*, 4> mapStack;
Vector<JSSet*, 4> setStack;

These Vector containers are not scanned by the Garbage Collector. If a garbage collection cycle is triggered during deserialization (for example via memory pressure or re-entrant JS execution), objects referenced only by these containers may be incorrectly collected.

The deserializer, however, continues to use these dangling pointers, resulting in a use-after-free condition.

Missing Fix

The official WebKit security patch (commit c9880de) replaces these containers with MarkedVector, a GC-aware structure that properly registers its contents as GC roots.

In the analyzed build:

  • MarkedVector is not implemented
  • CloneDeserializer still uses Vector
  • The GC does not scan these temporary object stacks

This confirms that the build is fully vulnerable to CVE-2023-28205.


Crash Analysis

The following crash was reliably triggered by the PoC and is consistent with a post-GC stale pointer dereference.

Key Indicators

  • Signal: SIGSEGV (11)
  • Fault address: 0x0000000000000068
  • Process: SceNKWebProcess
  • Module: libSceNKWebKit.sprx

The fault address 0x68 indicates a NULL base pointer dereference with an object-field offset, a classic signature of accessing a freed JavaScript object.

Register state confirms:

  • RAX = 0x0 (NULL object base)
  • Execution entirely within WebKit userland
  • No kernel or syscall involvement

This crash behavior is a direct manifestation of the CloneDeserializer UAF described above.


Crash Dump

Click to expand crash dump
Download Tool