Security features bypass in macOS - CVE-2023-41981
Published: September 26, 2023
Vulnerability identifier: #VU81161
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-41981
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to improper memory handling. A local user can bypass kernel memory mitigations and execute arbitrary code on the system.
Affected software
macOS
watchOS
iPadOS
Apple iOS
tvOS
watchOS
iPadOS
Apple iOS
tvOS
How to mitigate CVE-2023-41981
Install updates from vendor's website.
macOS - addressed in versions 14.0 23A344, 13.6 22G120
watchOS - update to 10.0
iPadOS - addressed in versions 16.7, 17.0
Apple iOS - addressed in versions 16.7 20H19, 17.0 21A326, 17.0 21A327, 17.0 21A329, 17.0 21A331
tvOS - update to 17.0
watchOS - update to 10.0
iPadOS - addressed in versions 16.7, 17.0
Apple iOS - addressed in versions 16.7 20H19, 17.0 21A326, 17.0 21A327, 17.0 21A329, 17.0 21A331
tvOS - update to 17.0