Memory corruption in Apple iOS and iPadOS - CVE-2023-27933
Published: March 27, 2023
Vulnerability identifier: #VU74083
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27933
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the OS kernel. A local privileged application (with root permissions) can trigger memory corruption and execute arbitrary code with kernel privileges.
Affected software
Apple iOS
iPadOS
watchOS
macOS
tvOS
iPadOS
watchOS
macOS
tvOS
How to mitigate CVE-2023-27933
Install updates from vendor's website.
Apple iOS - update to 16.4 20E247
iPadOS - update to 16.4 20E247
watchOS - update to 9.4 20T253
macOS - addressed in versions 12.6.4 21G526, 13.3 22E252
tvOS - update to 16.4 20L497
iPadOS - update to 16.4 20E247
watchOS - update to 9.4 20T253
macOS - addressed in versions 12.6.4 21G526, 13.3 22E252
tvOS - update to 16.4 20L497