Junglewise Threat Intelligence

CVE-2023-28206: Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

CVE-2023-28206 · Severity: critical · CVSS 8.6 · Exploited in the wild · Published 2023-04-10

Technologies: Cisco IOS, Apple macOS, Apple macOS Monterey, Apple watchOS, Apple iPadOS, Apple macOS Ventura. Vendors: Cisco, Apple.

Executive brief

An out-of-bounds write vulnerability in the IOSurfaceAccelerator component of Apple iOS, iPadOS, and macOS allows a local application to execute arbitrary code with kernel privileges. The issue was addressed through improved input validation and has been reported as being actively exploited in the wild.

Affected products

  • Apple iOS versions before 15.7.5, versions before 16.4.1
  • Apple iPadOS versions before 15.7.5, versions before 16.4.1
  • Apple macOS Ventura versions before 13.3.1
  • Apple macOS Monterey versions before 12.6.5
  • Apple macOS Big Sur versions before 11.7.6

Timeline

  • 2023-04-10: disclosed
  • 2023-04-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-04-10: patched: Fixed in iOS 16.4.1, iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5, iPadOS 15.7.5, macOS Monterey 12.6.5, and macOS Big Sur 11.7.6
  • exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats