CVE-2023-41974
גבוהה 7.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apple iOS and iPadOS Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-416
מוצרים מושפעים
apple: ipados; apple: iphone os
קישורים
- https://support.apple.com/en-us/120949 Release NotesVendor Advisory
- https://support.apple.com/en-us/126632 Release NotesVendor Advisory
- https://support.apple.com/en-us/HT213938 Release NotesVendor Advisory
- https://support.apple.com/kb/HT213938 Release NotesVendor Advisory
- https://cloud.google.com/blog/topics/threat-intelligence/coruna-powerful-ios-e… ExploitThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource