HIGH
CVE-2023-41974
CVSS
7.8
KEV
Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.
Summary dbcve.org
A use-after-free vulnerability in the iOS/iPadOS kernel allows a malicious application to execute arbitrary code with kernel-level privileges. The vulnerability stems from improper memory management where memory is accessed after being freed, potentially leading to memory corruption and privilege escalation from userland to kernel mode.
Mitigation
Apply the available iOS 17.x and iOS 15.8.7/iPadOS 15.8.7 security updates to affected devices to remediate this vulnerability.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
1.4%
Probability of exploitation in next 30 days
70.8th percentile
References
https://support.apple.com/en-us/120949
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126632
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213938
Release Notes, Vendor Advisory
https://support.apple.com/kb/HT213938
Release Notes, Vendor Advisory
https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-exploit-kit
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41974
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.