EXPOSURES › CVE-2023-41990
CVE-2023-41990
HIGH ⌖ ON CISA KEV · EXPLOITEDApple's iOS, iPadOS, macOS, tvOS, and watchOS contain a font-processing vulnerability enabling code execution.
This unspecified vulnerability allows attackers to execute arbitrary code by processing malicious font files across Apple's entire ecosystem, including devices used by defense contractors. DIB organizations must ensure all Apple devices are patched immediately to prevent unauthorized access and potential data exfiltration.
Shame score — While the vulnerability is actively exploited and affects multiple products, it is a known issue that Apple has disclosed and patched, making it less avoidable than negligent failures.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.