EXPOSURES › CVE-2023-32434
CVE-2023-32434
HIGH ⌖ ON CISA KEV · EXPLOITEDAn integer overflow vulnerability in Apple's operating systems allows applications to potentially execute code with kernel privileges, and is currently being exploited in the wild.
CVE-2023-32434 represents an integer overflow vulnerability affecting iOS, iPadOS, macOS, and watchOS, enabling potential code execution with kernel privileges. DIB organizations using these platforms must immediately apply Apple's security updates to mitigate the risk of unauthorized access and control. Failure to patch exposes systems to potential compromise and non-compliance with NIST 800-171 requirements.
Shame score — The vulnerability's active exploitation and potential for kernel-level code execution demonstrate a significant security oversight by Apple, impacting a wide range of devices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.