Junglewise Threat Intelligence

CVE-2023-38606: Apple Multiple Products Kernel Unspecified Vulnerability

CVE-2023-38606 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2023-07-26

Technologies: Apple macOS Monterey, Apple watchOS, Apple iPadOS, Apple Multiple Products, Apple macOS Ventura, Apple Tvos. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability in the kernel due to insufficient state management. A local application may exploit this flaw to modify sensitive kernel state, potentially bypassing security protections.

Affected products

  • Apple iOS before 15.7.8, before 16.6
  • Apple iPadOS before 15.7.8, before 16.6
  • Apple macOS Monterey before 12.6.8
  • Apple macOS Big Sur before 11.7.9
  • Apple macOS Ventura before 13.5
  • Apple tvOS before 16.6
  • Apple watchOS before 9.6

Timeline

  • 2023-07-26: disclosed
  • 2023-07-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-26: patched: Addressed in macOS Monterey 12.6.8, iOS 15.7.8, iPadOS 15.7.8, iOS 16.6, iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, and watchOS 9.6.
  • exploited: Apple is aware of reports that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

Related threats