Input validation error in iPadOS and Apple iOS - CVE-2023-41992

 

Input validation error in iPadOS and Apple iOS - CVE-2023-41992

Published: September 21, 2023 / Updated: May 30, 2025


Vulnerability identifier: #VU81040
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41992
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input within the OS kernel. A local application can execute arbitrary code on the system with elevated privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

iPadOS
Apple iOS
watchOS
macOS

How to mitigate CVE-2023-41992

Install updates from vendor's website.

iPadOS - addressed in versions 16.7, 17.0.1
Apple iOS - addressed in versions 16.7 20H19, 17.0.1 21A340
watchOS - addressed in versions 9.6.3, 10.0.1
macOS - addressed in versions 12.7 21G816, 13.6 22G120

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins