EXPOSURES › CVE-2023-28206
CVE-2023-28206
HIGH ⌖ ON CISA KEV · EXPLOITEDApple iOS, iPadOS, and macOS had a critical kernel-level vulnerability allowing apps to execute arbitrary code with kernel privileges.
Apple iOS, iPadOS, and macOS versions were found to have a kernel-level vulnerability that could allow malicious apps to execute arbitrary code with kernel privileges, posing a high security risk. This vulnerability has been actively exploited in the wild. DIB organizations should immediately assess the impact of this vulnerability on their systems and take necessary steps to mitigate the risk.
Shame score — Critical kernel-level vulnerability actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.