CERT-In Vulnerability Note
CIVN-2023-0303
Multiple Vulnerabilities in Apple iOS and iPadOS
Original Issue Date:October 14, 2023
Severity Rating: HIGH
Software Affected
- Apple iOS and iPadOS versions prior to 16.7.1
(Available for iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later)
Overview
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could be exploited by a remote attacker to gain elevated privileges and execute arbitrary code on the targeted system.
Description
These vulnerabilities exist in Apple iOS and iPadOS due to improper validation in kernel component and buffer overflow issue in WebRTC component. A remote attacker could exploit these vulnerabilities by sending a specially crafted request on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to gain elevated privileges and execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned in Apple Security updates:
https://support.apple.com/en-us/HT213972
Vendor Information
Apple
https://support.apple.com/en-us/HT213972
References
Apple
https://support.apple.com/en-us/HT213972
CVE Name
CVE-2023-42824
CVE-2023-5217
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|