Kernel Memory Mitigation Bypass in Apple iOS and watchOS
CVE-2023-32424

5.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
10 January 2024

Summary

A security vulnerability in Apple’s iOS and watchOS products allows an attacker with existing kernel code execution to potentially bypass protective measures designed to secure kernel memory. The vulnerability is addressed with enhanced memory handling protocols in the latest operating system updates for iOS, iPadOS, and watchOS, specifically in versions 16.4 and 9.4 respectively.

Affected Version(s)

iOS and iPadOS < 16.4

watchOS < 9.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.