Buffer overflow in Apple iOS and iPadOS - CVE-2023-38606

 

Buffer overflow in Apple iOS and iPadOS - CVE-2023-38606

Published: July 24, 2023


Vulnerability identifier: #VU78583
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-38606
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the OS kernel. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Apple iOS
iPadOS
watchOS
macOS
tvOS

How to mitigate CVE-2023-38606

Install updates from vendor's website.

Apple iOS - addressed in versions 15.7.8 19H364, 16.6 20G75
iPadOS - addressed in versions 15.7.8 19H364, 16.6
watchOS - update to 9.6 20U73
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.5 22G74
tvOS - update to 16.6

External References

Related Security Bulletins