HIGH
CVE-2023-41061
CVSS
7.8
KEV
Description
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Summary dbcve.org
This is a validation bypass vulnerability in iOS, iPadOS, and watchOS where processing a maliciously crafted attachment leads to arbitrary code execution. The vulnerability was actively exploited in the wild before the patches were released.
Mitigation
Apply the vendor-supplied updates: iOS 16.6.1, iPadOS 16.6.1, or watchOS 9.6.2 or later.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
3.78%
Probability of exploitation in next 30 days
89.5th percentile
References
http://seclists.org/fulldisclosure/2023/Sep/4
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2023/Sep/5
Mailing List, Third Party Advisory
https://support.apple.com/en-us/HT213905
Vendor Advisory
https://support.apple.com/en-us/HT213907
Vendor Advisory
https://support.apple.com/kb/HT213905
Vendor Advisory
https://support.apple.com/kb/HT213907
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41061
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.