Remote Code Execution Vulnerability in Apple Operating Systems
CVE-2023-40448
Summary
A severe vulnerability has been identified that impacts various Apple operating systems, including tvOS, iOS, iPadOS, watchOS, and macOS. This issue arises from inadequacies in protocol handling, allowing a remote attacker the potential to escape from the Web Content sandbox. The vulnerability has been rectified in the latest updates across the affected operating systems, highlighting the importance of timely software updates to mitigate the risks associated with this security flaw.
Affected Version(s)
iOS and iPadOS < 17
iOS and iPadOS < 16.7
macOS < 14
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved