Executive brief
An integer overflow vulnerability in multiple Apple operating systems allows an application to execute arbitrary code with kernel privileges. The issue was addressed through improved input validation across iOS, iPadOS, macOS, and watchOS.
Affected products
- Apple iOS Before 15.7.7, before 16.5.1
- Apple iPadOS Before 15.7.7, before 16.5.1
- Apple macOS Big Sur Before 11.7.8
- Apple macOS Monterey Before 12.6.7
- Apple macOS Ventura Before 13.4.1
- Apple watchOS Before 8.8.1, before 9.5.2
Timeline
- 2023-06-23: disclosed
- 2023-06-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-06-23: exploited: Apple reported awareness of active exploitation against versions of iOS released before iOS 15.7.