PT-2024-13027 · Apple · Apple Macos+3

Félix Poulin-Bélanger

·

Published

2024-01-01

·

Updated

2026-03-13

·

CVE-2023-41974

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple iOS versions prior to 17 Apple iPadOS versions prior to 17 Apple macOS versions prior to 14
Description This issue involves a use-after-free condition addressed through improved memory management. A malicious application may potentially execute arbitrary code with kernel privileges. Proof-of-concept (PoC) code has been released, and a researcher was awarded a $70,000 bounty for revealing the flaw. The vulnerability, also known as 'Landa', affects the XNU kernel. Exploitation does not necessarily lead to kernel corruption requiring cleanup to prevent a kernel panic. The issue is considered a Latest Known Exploited Vulnerability (KEV).
Recommendations Update Apple iOS to version 17 or later. Update Apple iPadOS to version 17 or later. Update Apple macOS to version 14 or later.

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2023-41974

Affected Products

Xnu Kernel
Ios
Ipados
Apple Macos