Executive brief
Apple iOS, iPadOS, and watchOS contain a validation issue in the Wallet component. A maliciously crafted attachment can lead to arbitrary code execution when processed by the affected device.
Affected products
- Apple iOS < 16.6.1
- Apple iPadOS < 16.6.1
- Apple watchOS < 9.6.2
Timeline
- 2023-09-07: disclosed: Initial publication by Apple
- 2023-09-07: patched: Fixed in watchOS 9.6.2, iOS 16.6.1, and iPadOS 16.6.1
- 2023-09-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-11: exploited: Apple and CISA confirmed reports of active exploitation in the wild.