Apple Arbitrary Remote Code Execution Vulnerability

Apple Arbitrary Remote Code Execution Vulnerability

On May 15, 2023 An Apple arbitrary code execution Vulnerability has been released.

Apple Arbitrary Remote Code Execution Vulnerability

The vulnerability is addressed with improved state management. A remote user may be able to cause unexpected app termination or arbitrary code execution according to the vulnerability. The problem is fixed in macOS Ventura 13.3, iOS 15.7.4 and iPadOS 15.7.4, Safari 16.4, iOS 16.4 and iPadOS 16.4. (CVE-2023-28201)

Affected Systems

  • cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*Up to (excluding) 15.7.4
  • cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*From (including) 16.0 Up to (excluding) 16.4
  • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*Up to (excluding) 13.3
  • cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* Up to (excluding) 16.4
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*From (including) 16.0 Up to (excluding) 16.4
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*Up to (excluding) 15.7.4

IoC’s

-

Recommended Solution(s)

-

Mitigations

-

CVE / CWE

CVE-2023-28201

Related Website(s)

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.