First published: Mon Mar 27 2023(Updated: )
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. An app may be able to execute arbitrary code with kernel privileges.
Credit: Xinru Chi Pangu LabNed Williamson Google Project ZeroAdam Doupé ASU SEFCOMAdam Doupé ASU SEFCOMAdam Doupé ASU SEFCOMAdam Doupé ASU SEFCOMAdam Doupé ASU SEFCOM product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <16.4 | 16.4 |
Apple watchOS | <9.4 | 9.4 |
Apple iOS | <15.7.4 | 15.7.4 |
Apple iPadOS | <15.7.4 | 15.7.4 |
Apple Ipad Os | <15.7.4 | |
Apple Ipad Os | >=16.0<16.4 | |
Apple iPhone OS | <15.7.4 | |
Apple iPhone OS | >=16.0<16.4 | |
Apple macOS | >=13.0<13.3 | |
Apple tvOS | <16.4 | |
Apple watchOS | <9.4 | |
<16.4 | 16.4 | |
<16.4 | 16.4 | |
Apple macOS Ventura | <13.3 | 13.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-27969 is a use after free vulnerability in the kernel of Apple devices.
CVE-2023-27969 has a severity rating of 7.8 out of 10, which is considered high.
Devices running watchOS up to version 9.4, tvOS up to version 16.4, iOS up to version 15.7.4, iPadOS up to version 15.7.4, iOS up to version 16.4, and iPadOS up to version 16.4 are affected by CVE-2023-27969.
To fix CVE-2023-27969, update your device to the latest version of watchOS, tvOS, iOS, or iPadOS available.
You can find more information about CVE-2023-27969 on the Apple support website.