CVE-2023-28206

Description from NVD

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.7.5 and iPadOS 15.7.5, macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Big Sur 11.7.6, macOS Ventura 13.3.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

Information Acquisition Date:2023-04-30T16:40Z
CVSS 2.0: 0.0 None CVSS 3.x: 8.6 HIGH

▼ CVSS3 Vec CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

NVD References

 https://support.apple.com/en-us/HT213724
     source:MISC
     tags:Release Notes    
 https://support.apple.com/en-us/HT213725
     source:MISC
     tags:Release Notes    
 https://support.apple.com/en-us/HT213723
     source:MISC
     tags:Release Notes    
 https://support.apple.com/en-us/HT213720
     source:MISC
     tags:Release Notes    
 https://support.apple.com/en-us/HT213721
     source:MISC
     tags:Release Notes    
 20230410 APPLE-SA-2023-04-07-2 macOS Ventura 13.3.1
     source:FULLDISC
     tags:Mailing List    Release Notes    
 20230410 APPLE-SA-2023-04-07-1 iOS 16.4.1 and iPadOS 16.4.1
     source:FULLDISC
     tags:Mailing List    Release Notes    
 20230410 APPLE-SA-2023-04-10-1 iOS 15.7.5 and iPadOS 15.7.5
     source:FULLDISC
     tags:Mailing List    Release Notes    
 20230410 APPLE-SA-2023-04-10-2 macOS Monterey 12.6.5
     source:FULLDISC
     tags:Mailing List    Release Notes    
 20230410 APPLE-SA-2023-04-10-3 macOS Big Sur 11.7.6
     source:FULLDISC
     tags:Mailing List    Release Notes    

This vulnerability may involve a PoC.

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: Android(1 tweets) Apple(86 tweets) Linux(1 tweets) iOS(98 tweets)



List of frequently cited URLs

URLNum of Times Referred to
https://cvetrends.com37
https://www.cisa.gov/known-exploited-vulnerabilities-catalog9
https://go.dhs.gov/Z3Q7
https://gist.github.com/LinusHenze/728db96a836b6817ecb727cf...7
https://www.helpnetsecurity.com/2023/04/11/cve-2023-28205-c...6
https://applech2.com/archives/20230411-cve-2023-28206-poc.html4
https://support.apple.com/en-us/HT2137204
https://securityonline.info/apple-users-face-two-actively-e...4
https://twitter.com/LinusHenze/status/16453403485483008013
https://www.idownloadblog.com/2023/04/10/linus-henze-poc-cv...3

▼ Show Information from Twitter(195)


List of frequently cited URLs

URLNum of Times Referred to
cvetrends.com37
www.cisa.gov9
go.dhs.gov7
gist.github.com7
www.helpnetsecurity.com6
applech2.com4
support.apple.com4
securityonline.info4
twitter.com3
www.idownloadblog.com3

▼ Show Information from Twitter(195)


GitHub Search Results: Up to 10
NameURL
ZZY3312/CVE-2023-28206 https://github.com/ZZY3312/CVE-2023-28206

GitHub Search Results: Up to 10
NameURL
ZZY3312/CVE-2023-28206 github.com

2023/04/30 Score : 0
Added Har-sia Database : 2023/04/08
Last Modified : 2023/04/30
Highest Scored Date : 2023/04/11
Highest Score : 64