Executive brief
A kernel privilege escalation vulnerability in Apple products was addressed with improved checks. A local attacker may be able to elevate their privileges; Apple is aware of reports that this issue was actively exploited in the wild against versions of iOS prior to 16.7.
Affected products
- Apple iOS before 16.7
- Apple iPadOS before 16.7
- Apple macOS Monterey before 12.7
- Apple macOS Ventura before 13.6
Timeline
- 2023-09-21: patched: Fixed in macOS Monterey 12.7, iOS 16.7, iPadOS 16.7, and macOS Ventura 13.6.
- 2023-09-25: disclosed
- 2023-09-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2023-09-25: exploited: Apple reported awareness of active exploitation.