CERT-In Vulnerability Note
CIVN-2023-0048
Multiple Vulnerabilities in Apple Products
Original Issue Date:February 15, 2023
Severity Rating: HIGH
Software Affected
- Apple iOS and iPadOS versions prior to 16.3.1 for iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
- Apple macOS Ventura versions prior to 13.2.1
Overview
Multiple vulnerabilities have been reported in Apple products which could allow an attacker to gain elevated privileges, execute arbitrary code with kernel privileges and gain access to sensitive information on the targeted system.
Description
These vulnerabilities exist in Apple products due to use after free issue in Kernel, improper handling of temporary files in Shortcuts and type confusion issue in WebKit component. An attacker could exploit these vulnerabilities by sending maliciously crafted web content and trigger memory corruption error.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges, execute arbitrary code with kernel privileges and gain access to sensitive information on the targeted system.
Solution
Apply appropriate software updates as mentioned in the Apple Security updates:
https://support.apple.com/en-us/HT213635
https://support.apple.com/en-us/HT213633
Vendor Information
Apple
https://support.apple.com/en-us/HT213635
https://support.apple.com/en-us/HT213633
References
Apple
https://support.apple.com/en-us/HT213635
https://support.apple.com/en-us/HT213633
CVE Name
CVE-2023-23514
CVE-2023-23522
CVE-2023-23529
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|