First published: Wed Oct 25 2023(Updated: )
FairPlay. The issue was addressed with improved bounds checks.
Credit: Peter Nguyễn Vũ Hoàng @peternguyen14 STAR Labs SG Pte product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS, iPadOS, and watchOS | <17.1 | 17.1 |
Apple iOS, iPadOS, and watchOS | <17.1 | 17.1 |
iPadOS | <17.1 | |
iStyle @cosme iPhone OS | <17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2023-42928 has been assessed as a critical vulnerability due to its potential to allow an app to gain elevated privileges.
To mitigate CVE-2023-42928, update your device to iOS 17.1 or iPadOS 17.1.
CVE-2023-42928 affects devices running iOS versions prior to 17.1 and iPadOS versions prior to 17.1.
No, updating to iOS 17.1 or iPadOS 17.1 resolves the risk associated with CVE-2023-42928.
CVE-2023-42928 is a privilege escalation vulnerability due to inadequate bounds checking.