Integer overflow in Apple iOS and iPadOS - CVE-2023-32434
Published: June 21, 2023 / Updated: September 12, 2025
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to an integer overflow within the OS kernel. A local application can trigger an integer overflow and execute arbitrary code with kernel privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
iPadOS
watchOS
macOS
How to mitigate CVE-2023-32434
iPadOS - addressed in versions 15.7.7 19H357, 15.8 19H370, 16.5.1
watchOS - addressed in versions 8.8.1, 9.5.1 20T570
macOS - addressed in versions 11.7.8 20G1351, 12.6.7 21G651, 13.4.1 22F82
Links to Public Exploits and PoC-codes
- Exploit #11947 - oob_entry (oob_entry tfp0 kernel exploit for armv7 iOS (iOS 3.0–10.3.4), using CVE-2023-32434. We will publish a write-up detailing the methods in the coming weeks. ?) (September 12, 2025)
- Exploit #11191 - Trigon (Deterministic kernel exploit based on CVE-2023-32434.) (March 4, 2025)
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS and iPadOS
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in macOS Ventura
- Privilege escalation in macOS Monterey
- Privilege escalation in macOS Big Sur
- Privilege escalation in Apple watchOS 8
- Privilege escalation in Apple watchOS 9
- Privilege escalation in Apple iOS 15 and iPadOS 15