Buffer overflow in Apple iOS and iPadOS - CVE-2023-23540
Published: March 27, 2023
Vulnerability identifier: #VU74063
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23540
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the Apple Neural Engine feature. A local application can trigger memory corruption and execute arbitrary code with kernel privileges.
Affected software
Apple iOS
iPadOS
macOS
Operational Decision Manager
iPadOS
macOS
Operational Decision Manager
How to mitigate CVE-2023-23540
Install updates from vendor's website.
Apple iOS - addressed in versions 16.4 20E247, 15.7.8 19H364
iPadOS - addressed in versions 16.4 20E247, 15.7.8 19H364
macOS - addressed in versions 11.7.5 20G1225, 12.6.4 21G526
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
iPadOS - addressed in versions 16.4 20E247, 15.7.8 19H364
macOS - addressed in versions 11.7.5 20G1225, 12.6.4 21G526
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5