CVE-2023-41064
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 15% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-120
מוצרים מושפעים
apple: ipados; apple: iphone os; apple: macos
קישורים
- https://support.apple.com/en-us/HT213905 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213906 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213913 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213914 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213915 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213905 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213906 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213913 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213914 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213915 Release NotesVendor Advisory