Buffer overflow in iPadOS and Apple iOS - CVE-2023-42824

 

Buffer overflow in iPadOS and Apple iOS - CVE-2023-42824

Published: October 4, 2023


Vulnerability identifier: #VU81493
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-42824
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error within the OS kernel. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.

Note, the vulnerability is being actively exploited in the wild.


Affected software

iPadOS
Apple iOS

How to mitigate CVE-2023-42824

Install updates from vendor's website.

iPadOS - addressed in versions 17.0.3, 16.7.1
Apple iOS - addressed in versions 17.0.3 21A360, 16.7.1 20H30

External References

Related Security Bulletins