CVE-2023-32434
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple Multiple Products Integer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 52% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-190
מוצרים מושפעים
apple: ipados; apple: iphone os; apple: macos; apple: watchos
קישורים
- https://support.apple.com/en-us/HT213808 Vendor Advisory
- https://support.apple.com/en-us/HT213809 Vendor Advisory
- https://support.apple.com/en-us/HT213810 Vendor Advisory
- https://support.apple.com/en-us/HT213811 Vendor Advisory
- https://support.apple.com/en-us/HT213812 Vendor Advisory
- https://support.apple.com/en-us/HT213813 Vendor Advisory
- https://support.apple.com/en-us/HT213814 Vendor Advisory
- https://support.apple.com/kb/HT213990 Vendor Advisory
- https://support.apple.com/en-us/HT213808 Vendor Advisory
- https://support.apple.com/en-us/HT213809 Vendor Advisory