PT-2023-4994 · Apple · Macos Ventura+6

Published

2023-08-22

·

Updated

2026-02-06

·

CVE-2023-41064

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple iOS, iPadOS, and macOS versions prior to 16.6.1 Apple macOS Monterey versions prior to 12.6.9 Apple macOS Ventura versions prior to 13.5.2 Apple iOS versions prior to 15.7.9 Apple iPadOS versions prior to 15.7.9 Apple macOS Big Sur versions prior to 11.7.10
Description A buffer overflow issue exists in the ImageIO component of Apple iOS, iPadOS, and macOS. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of reports that this issue has been actively exploited in attacks such as BLASTPASS, which leveraged PassKit attachments containing malicious images. The vulnerability has been linked to the Pegasus spyware. The issue is related to a flaw in the handling of images and may allow an attacker to execute code on a targeted device.
Recommendations Update to iOS 16.6.1 or later. Update to iPadOS 16.6.1 or later. Update to macOS Ventura 13.5.2 or later. Update to iOS 15.7.9 or later. Update to iPadOS 15.7.9 or later. Update to macOS Monterey 12.6.9 or later. Update to macOS Big Sur 11.7.10 or later.

Exploit

Fix

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-05533
CVE-2023-41064

Affected Products

Imageio
Apple Macos
Ios
Ipados
Macos Big Sur
Macos Monterey
Macos Ventura