Arbitrary Code Execution Vulnerability in iOS 17
CVE-2023-41974

7.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
10 January 2024

Summary

A vulnerability related to use-after-free has been identified in Apple's iOS and iPadOS systems, leading to potential exploitation where an application could execute arbitrary code with kernel privileges. This issue has been addressed through improved memory management strategies in the latest versions, making it crucial for users to update to the latest iOS 17 and iPadOS 17 to ensure device security. Prior versions are susceptible to this flaw, highlighting the importance of maintaining up-to-date software to mitigate risks.

Affected Version(s)

iOS and iPadOS < 17

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.