Junglewise Threat Intelligence

CVE-2023-41061: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

CVE-2023-41061 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-09-11

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

Apple iOS, iPadOS, and watchOS contain a validation issue in the Wallet component. A maliciously crafted attachment can lead to arbitrary code execution when processed by the affected device.

Affected products

  • Apple iOS < 16.6.1
  • Apple iPadOS < 16.6.1
  • Apple watchOS < 9.6.2

Timeline

  • 2023-09-07: disclosed: Initial publication by Apple
  • 2023-09-07: patched: Fixed in watchOS 9.6.2, iOS 16.6.1, and iPadOS 16.6.1
  • 2023-09-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-11: exploited: Apple and CISA confirmed reports of active exploitation in the wild.

Related threats