Junglewise Threat Intelligence

CVE-2023-41064: Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability

CVE-2023-41064 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-09-11

Technologies: Cisco IOS, Apple macOS, Apple macOS Ventura, Apple watchOS, Apple macOS Monterey, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

A buffer overflow vulnerability in Apple's ImageIO framework allows for arbitrary code execution when processing a maliciously crafted image. The issue was addressed through improved memory handling across multiple Apple operating systems.

Affected products

  • Apple iOS up to 15.7.9, 16.0 to 16.6.1
  • Apple iPadOS up to 15.7.9, 16.0 to 16.6.1
  • Apple macOS Monterey up to 12.6.9
  • Apple macOS Ventura up to 13.5.2
  • Apple macOS Big Sur up to 11.7.10

Timeline

  • 2023-09-11: disclosed
  • 2023-09-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-11: patched: Fixed in iOS 16.6.1, iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9, iPadOS 15.7.9, and macOS Big Sur 11.7.10
  • 2023-09-11: exploited: Apple is aware of reports that this issue may have been actively exploited.

Related threats