PT-2023-3221 · Apple · Apple Macos+3
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
watchOS versions prior to 9.5.2
watchOS versions prior to 8.8.1
macOS Big Sur versions prior to 11.7.8
macOS Monterey versions prior to 12.6.7
macOS Ventura versions prior to 13.4.1
iOS versions prior to 15.7.7
iOS versions prior to 16.5.1
iPadOS versions prior to 15.7.7
iPadOS versions prior to 16.5.1
Description
An integer overflow occurs due to insufficient input validation, which may allow an application to execute arbitrary code with kernel privileges. An integer overflow is a condition where an arithmetic operation attempts to create a numeric value that is outside of the range that can be represented with a given number of bits. This issue has been reported as actively exploited against versions of iOS released before iOS 15.7. In real-world incidents, this flaw was used as part of a sophisticated spyware campaign to gain root privileges on target devices, enabling the deployment of a backdoor for stealing iCloud keychain data, recording microphone audio, and tracking location.
Recommendations
Update watchOS to version 9.5.2.
Update watchOS to version 8.8.1.
Update macOS Big Sur to version 11.7.8.
Update macOS Monterey to version 12.6.7.
Update macOS Ventura to version 13.4.1.
Update iOS to version 15.7.7.
Update iOS to version 16.5.1.
Update iPadOS to version 15.7.7.
Update iPadOS to version 16.5.1.
Exploit
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apple Macos
Ios
Ipados
Watchos