Junglewise Threat Intelligence

CVE-2023-42824: Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

CVE-2023-42824 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-10-05

Technologies: Cisco IOS, Apple macOS, Apple watchOS, Apple iPadOS. Vendors: Cisco, Apple.

Executive brief

A kernel privilege escalation vulnerability in Apple iOS and iPadOS allows a local attacker to elevate their privileges. The issue was addressed with improved checks and has been reported as actively exploited in the wild against versions prior to iOS 16.6.

Affected products

  • Apple iOS < 16.7.1, 17.0 to < 17.0.3
  • Apple iPadOS < 16.7.1, 17.0 to < 17.0.3

Timeline

  • 2023-10-05: disclosed
  • 2023-10-05: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-25: patched: Fixed in iOS/iPadOS 16.7.1 and 17.0.3
  • 2023-10-05: exploited: Apple aware of reports of active exploitation against versions before iOS 16.6

Related threats