Executive brief
A buffer overflow vulnerability in Apple's ImageIO framework allows for arbitrary code execution when processing a maliciously crafted image. The issue was addressed through improved memory handling across multiple Apple operating systems.
Affected products
- Apple iOS up to 15.7.9, 16.0 to 16.6.1
- Apple iPadOS up to 15.7.9, 16.0 to 16.6.1
- Apple macOS Monterey up to 12.6.9
- Apple macOS Ventura up to 13.5.2
- Apple macOS Big Sur up to 11.7.10
Timeline
- 2023-09-11: disclosed
- 2023-09-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-11: patched: Fixed in iOS 16.6.1, iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9, iPadOS 15.7.9, and macOS Big Sur 11.7.10
- 2023-09-11: exploited: Apple is aware of reports that this issue may have been actively exploited.