CVE-2023-41061

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted...

Basic Information

CVE State
PUBLISHED
Reserved Date
August 22, 2023
Published Date
September 07, 2023
Last Updated
February 13, 2025
Vendor
Apple
Product
iOS and iPadOS, watchOS
Description
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVSS Scores

CVSS v3.1

7.8 - HIGH

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
Active
Automatable
Yes
Technical Impact
Total

Exploit Status

Exploited in the Wild
Yes (added 2023-09-11 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-09-11 00:00:00 UTC