Buffer overflow in Apple iOS - CVE-2023-41990
Published: September 11, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in FontParser. A remote attacker can trick the victim to open a specially crafted file or visit a malicious website, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, the vulnerability is being actively exploited in the wild.
Affected software
watchOS
macOS
iPadOS
tvOS
How to mitigate CVE-2023-41990
watchOS - update to 9.3 20S648
macOS - addressed in versions 11.7.9 20G1426, 12.6.8 21G725, 13.2 22D49
iPadOS - update to 16.3 20D47
tvOS - update to 16.3 20K650
External References
Related Security Bulletins
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple macOS Ventura
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur