Junglewise Threat Intelligence

CVE-2023-41990: Apple Multiple Products Code Execution Vulnerability

CVE-2023-41990 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2024-01-08

Technologies: Apple macOS Monterey, Apple iPadOS, Apple watchOS, Apple Multiple Products, Apple macOS Ventura, Apple Tvos. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a vulnerability in the handling of font files. Processing a specially crafted font file may lead to arbitrary code execution due to improper handling of caches.

Affected products

  • Apple iOS before 15.7.1
  • Apple iPadOS before 15.7.1
  • Apple macOS Monterey before 12.6.8
  • Apple macOS Big Sur before 11.7.9
  • Apple macOS Ventura before 13.2
  • Apple tvOS before 16.3
  • Apple watchOS before 9.3

Timeline

  • 2023-01-23: patched: Fixed in iOS 16.3, iPadOS 16.3, macOS Ventura 13.2, tvOS 16.3, and watchOS 9.3.
  • 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-01-08: disclosed: NVD publication date.
  • 2024-01-08: exploited: Apple reported awareness of active exploitation against versions of iOS released before iOS 15.7.1.

Related threats