CERT-In Advisory
CIAD-2023-0043
Multiple Vulnerabilities in Apple Products
Original Issue Date: December 01, 2023
Severity Rating: High
Software Affected
- Apple iOS & iPadOS versions prior to 17.1.2 (iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later)
- Apple macOS Sonoma versions prior to 14.2
- Apple Safari versions prior to 17.1.2
Overview
Multiple vulnerabilities have been reported in Apple Products which could be exploited by an attacker to disclose sensitive information and execute arbitrary code on the targeted system.
Description
These vulnerabilities exist in Apple Products due to out-of-bounds read and memory corruption flaws in WebKit component.
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information and execute arbitrary code on a targeted system.
Note: It has been reported that vulnerabilities (CVE-2023-42916 & CVE-2023-42917) may have been exploited against versions of iOS before iOS 16.7.1. Users are advised to apply patches urgently.
Solution
Apply appropriate updates as mentioned in Apple Security updates:
https://support.apple.com/en-us/HT201222
Vendor Information
Apple
https://support.apple.com/en-us/HT201222
References
https://support.apple.com/en-us/HT201222
CVE Name
CVE-2023-42916
CVE-2023-42917
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|