Input validation error in iPadOS and Apple iOS - CVE-2023-41992
Published: September 21, 2023 / Updated: May 30, 2025
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insufficient validation of user-supplied input within the OS kernel. A local application can execute arbitrary code on the system with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apple iOS
watchOS
macOS
How to mitigate CVE-2023-41992
Apple iOS - addressed in versions 16.7 20H19, 17.0.1 21A340
watchOS - addressed in versions 9.6.3, 10.0.1
macOS - addressed in versions 12.7 21G816, 13.6 22G120