CVE-2023-41974
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to run any code they want on a device with full system access, which could lead to complete control over the device. It requires the attacker to trick the user into running a malicious app on iPadOS or iOS versions prior to the latest updates.
Technical Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Jan 10, 2024
about 2 years ago
Last Modified
Mar 12, 2026
26 days ago
Vendor
apple
Product
ipados
Related Vulnerabilities
This vulnerability allows an attacker to potentially execute harmful code on a user's device by tricking them into viewing specially crafted web content. It primarily affects users of Safari on specific versions of macOS and iOS, and requires the victim to visit a malicious website for the attack to succeed.
An attacker can use a malicious human interface device (like a keyboard or mouse) to crash processes on iPads running specific versions of the operating system. This requires the attacker to physically connect their harmful device to the iPad, making it a localized threat.
This vulnerability allows an attacker to run their own harmful code on your device by tricking it into processing specially crafted web content. It can be exploited when users visit malicious websites, so keeping your device updated is crucial to protect against potential attacks.
This vulnerability allows an attacker to run harmful code on a user's device by tricking them into visiting a specially crafted website. It requires the user to open a malicious webpage in Safari, which could compromise their device and data.