Junglewise Threat Intelligence

CVE-2023-41992: Apple Multiple Products Kernel Privilege Escalation Vulnerability

CVE-2023-41992 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-09-25

Technologies: Apple macOS Monterey, Apple macOS Ventura, Apple Multiple Products, Apple iPadOS. Vendors: Apple.

Executive brief

A kernel privilege escalation vulnerability in Apple products was addressed with improved checks. A local attacker may be able to elevate their privileges; Apple is aware of reports that this issue was actively exploited in the wild against versions of iOS prior to 16.7.

Affected products

  • Apple iOS before 16.7
  • Apple iPadOS before 16.7
  • Apple macOS Monterey before 12.7
  • Apple macOS Ventura before 13.6

Timeline

  • 2023-09-21: patched: Fixed in macOS Monterey 12.7, iOS 16.7, iPadOS 16.7, and macOS Ventura 13.6.
  • 2023-09-25: disclosed
  • 2023-09-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2023-09-25: exploited: Apple reported awareness of active exploitation.

Related threats