Buffer overflow in Apple iOS - CVE-2023-41990

 

Buffer overflow in Apple iOS - CVE-2023-41990

Published: September 11, 2023


Vulnerability identifier: #VU80589
CSH Severity: Critical
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41990
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in FontParser. A remote attacker can trick the victim to open a specially crafted file or visit a malicious website, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Note, the vulnerability is being actively exploited in the wild.


Affected software

Apple iOS
watchOS
macOS
iPadOS
tvOS

How to mitigate CVE-2023-41990

Install updates from vendor's website.

Apple iOS - addressed in versions 15.7.8 19H364, 16.3 20D47
watchOS - update to 9.3 20S648
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.2 22D49
iPadOS - update to 16.3 20D47
tvOS - update to 16.3 20K650

External References

Related Security Bulletins