HIGH

CVE-2023-41974

Apple Ipados 2024-01-10 CVSS v3.1
CVSS
7.8
KEV

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.

Summary dbcve.org

A use-after-free vulnerability in the iOS/iPadOS kernel allows a malicious application to execute arbitrary code with kernel-level privileges. The vulnerability stems from improper memory management where memory is accessed after being freed, potentially leading to memory corruption and privilege escalation from userland to kernel mode.

Mitigation

Apply the available iOS 17.x and iOS 15.8.7/iPadOS 15.8.7 security updates to affected devices to remediate this vulnerability.

Proof of Concept

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

1.4%
Probability of exploitation in next 30 days
70.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE