HIGH

CVE-2023-41061

Apple Ipados 2023-09-07 CVSS v3.1
CVSS
7.8
KEV

Description

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Summary dbcve.org

This is a validation bypass vulnerability in iOS, iPadOS, and watchOS where processing a maliciously crafted attachment leads to arbitrary code execution. The vulnerability was actively exploited in the wild before the patches were released.

Mitigation

Apply the vendor-supplied updates: iOS 16.6.1, iPadOS 16.6.1, or watchOS 9.6.2 or later.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

3.78%
Probability of exploitation in next 30 days
89.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE