CVE-2023-28206
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Published
2023-04-10T19:15:07.273
Last Modified
2025-10-23T18:02:39.480
Status
Analyzed
Source
[email protected]
Severity
CVSSv3.1: 8.6 (HIGH)
Weaknesses
-
Type: Primary
CWE-787
-
Type: Secondary
CWE-787
Affected Vendors & Products
References
-
https://support.apple.com/en-us/HT213720
Release Notes, Vendor Advisory
([email protected])
-
https://support.apple.com/en-us/HT213721
Release Notes, Vendor Advisory
([email protected])
-
https://support.apple.com/en-us/HT213723
Release Notes, Vendor Advisory
([email protected])
-
https://support.apple.com/en-us/HT213724
Release Notes, Vendor Advisory
([email protected])
-
https://support.apple.com/en-us/HT213725
Release Notes, Vendor Advisory
([email protected])
-
https://support.apple.com/en-us/HT213720
Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/en-us/HT213721
Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/en-us/HT213723
Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/en-us/HT213724
Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://support.apple.com/en-us/HT213725
Release Notes, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28206
US Government Resource
(134c704f-9b21-4f2e-91b3-4a467353bcc0)