First published: Thu May 18 2023(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, iOS 16.5 and iPadOS 16.5. An app may be able to disclose kernel memory.
Credit: Linus Henze Pinauten GmbHLinus Henze Pinauten GmbHLinus Henze Pinauten GmbH product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
<16.5 | 16.5 | |
<16.5 | 16.5 | |
Apple tvOS | <16.5 | 16.5 |
Apple watchOS | <9.5 | 9.5 |
Apple iPadOS | <16.5 | |
Apple iPhone OS | <16.5 | |
Apple tvOS | <16.5 | |
Apple watchOS | <9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-32354 is a vulnerability in IOSurfaceAccelerator where an out-of-bounds read can occur due to improved input validation.
The severity of CVE-2023-32354 is medium with a severity value of 5.5.
CVE-2023-32354 affects Apple iPhone OS, Apple iPadOS, Apple tvOS, and Apple watchOS. The affected versions are up to, but not including, iOS, iPadOS, tvOS 16.5 and watchOS 9.5 respectively.
To fix the CVE-2023-32354 vulnerability, update to watchOS 9.5, tvOS 16.5, iOS 16.5, or iPadOS 16.5.
Yes, an app exploiting the CVE-2023-32354 vulnerability may be able to disclose kernel memory.