Buffer overflow in Apple iOS and iPadOS - CVE-2023-38606
Published: July 24, 2023
Vulnerability identifier: #VU78583
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38606
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error within the OS kernel. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
iPadOS
watchOS
macOS
tvOS
iPadOS
watchOS
macOS
tvOS
How to mitigate CVE-2023-38606
Install updates from vendor's website.
Apple iOS - addressed in versions 15.7.8 19H364, 16.6 20G75
iPadOS - addressed in versions 15.7.8 19H364, 16.6
watchOS - update to 9.6 20U73
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
tvOS - update to 16.6
iPadOS - addressed in versions 15.7.8 19H364, 16.6
watchOS - update to 9.6 20U73
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
tvOS - update to 16.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur