Executive brief
A kernel privilege escalation vulnerability in Apple iOS and iPadOS allows a local attacker to elevate their privileges. The issue was addressed with improved checks and has been reported as actively exploited in the wild against versions prior to iOS 16.6.
Affected products
- Apple iOS < 16.7.1, 17.0 to < 17.0.3
- Apple iPadOS < 16.7.1, 17.0 to < 17.0.3
Timeline
- 2023-10-05: disclosed
- 2023-10-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-10-25: patched: Fixed in iOS/iPadOS 16.7.1 and 17.0.3
- 2023-10-05: exploited: Apple aware of reports of active exploitation against versions before iOS 16.6