PT-2023-5473 · Apple · Ipados+5

Bill Marczak

+1

·

Publicado

2023-09-06

·

Atualizado

2025-12-08

·

CVE-2023-41992

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple macOS versions prior to 12.7 Apple iOS versions prior to 16.7 Apple iPadOS versions prior to 16.7 Apple watchOS versions prior to 9.6.3 Apple macOS Ventura versions prior to 13.6 Apple watchOS versions prior to 10.0.1 Apple iPadOS versions prior to 17.0.1 Apple iOS versions prior to 17.0.1
Description The issue involves insufficient checks when processing web content within the kernel of iOS, watchOS, iPadOS, and macOS, potentially allowing an attacker to elevate their privileges. Reports indicate that this issue may have been actively exploited in versions of iOS prior to iOS 16.7. The vulnerability allows malicious applications to bypass signature validation and gain elevated privileges. The issue was addressed by implementing improved checks. The vulnerability affects multiple Apple platforms. Technical details reveal the exploitation involves triggering a bug on an old thread, invoking ipc entry grow table() through mach port allocate name(), and subsequently calling mach thread self() to obtain a new mach name.
Recommendations Update macOS to version 12.7 or later. Update iOS to version 16.7 or later. Update iPadOS to version 16.7 or later. Update watchOS to version 9.6.3 or later. Update macOS Ventura to version 13.6 or later. Update watchOS to version 10.0.1 or later. Update iPadOS to version 17.0.1 or later. Update iOS to version 17.0.1 or later.

Correção

LPE

Improper Check for Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-06112
CVE-2023-41992

Produtos afetados

Apple Macos
Ios
Ipados
Macos Monterey
Macos Ventura
Watchos