Junglewise Threat Intelligence

CVE-2023-41974: Apple iOS and iPadOS use-after-free in kernel

CVE-2023-41974 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2026-03-05

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

Apple iOS and iPadOS devices are affected by a security flaw that could allow a malicious application to take full control of the device. By exploiting this vulnerability, an app can gain the highest level of system privileges, potentially allowing it to access sensitive data or disrupt device operations. This issue has been reported as being actively exploited in the wild.

Technical details

A use-after-free (CWE-416) vulnerability exists in the kernel of Apple iOS and iPadOS due to improper memory management. A local attacker can exploit this by running a specially crafted application on the target device. Successful exploitation allows the application to escape its sandbox and execute arbitrary code with kernel-level privileges, leading to full system compromise. This vulnerability has been observed in active exploitation. Apple addressed the issue by improving memory management in iOS/iPadOS 17 and iOS/iPadOS 15.8.7.

Affected products

  • Apple iOS < 17.0, < 15.8.7
  • Apple iPadOS < 17.0, < 15.8.7

Timeline

  • 2024-01-10: disclosed: Initial disclosure by Apple
  • 2026-03-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-03-05: advisory: NVD publication date

Related threats