Remote Code Execution Vulnerability in Apple Operating Systems
CVE-2023-40448

8.6HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
27 September 2023

Badges

👾 Exploit Exists🟡 Public PoC

Summary

A severe vulnerability has been identified that impacts various Apple operating systems, including tvOS, iOS, iPadOS, watchOS, and macOS. This issue arises from inadequacies in protocol handling, allowing a remote attacker the potential to escape from the Web Content sandbox. The vulnerability has been rectified in the latest updates across the affected operating systems, highlighting the importance of timely software updates to mitigate the risks associated with this security flaw.

Affected Version(s)

iOS and iPadOS < 17

iOS and iPadOS < 16.7

macOS < 14

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.