CVE-2023-41974

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to run any code they want on a device with full system access, which could lead to complete control over the device. It requires the attacker to trick the user into running a malicious app on iPadOS or iOS versions prior to the latest updates.

Technical Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.

CVSS Vector Analysis

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References