PT-2023-3221 · Apple · Apple Macos+3

·

CVE-2023-32434

·

Published

2023-06-21

·

Updated

2026-06-28

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions watchOS versions prior to 9.5.2 watchOS versions prior to 8.8.1 macOS Big Sur versions prior to 11.7.8 macOS Monterey versions prior to 12.6.7 macOS Ventura versions prior to 13.4.1 iOS versions prior to 15.7.7 iOS versions prior to 16.5.1 iPadOS versions prior to 15.7.7 iPadOS versions prior to 16.5.1
Description An integer overflow occurs due to insufficient input validation, which may allow an application to execute arbitrary code with kernel privileges. An integer overflow is a condition where an arithmetic operation attempts to create a numeric value that is outside of the range that can be represented with a given number of bits. This issue has been reported as actively exploited against versions of iOS released before iOS 15.7. In real-world incidents, this flaw was used as part of a sophisticated spyware campaign to gain root privileges on target devices, enabling the deployment of a backdoor for stealing iCloud keychain data, recording microphone audio, and tracking location.
Recommendations Update watchOS to version 9.5.2. Update watchOS to version 8.8.1. Update macOS Big Sur to version 11.7.8. Update macOS Monterey to version 12.6.7. Update macOS Ventura to version 13.4.1. Update iOS to version 15.7.7. Update iOS to version 16.5.1. Update iPadOS to version 15.7.7. Update iPadOS to version 16.5.1.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03341
CVE-2023-32434

Affected Products

Apple Macos
Ios
Ipados
Watchos