Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilitywidely-deployed-product-advisoryproof-of-concept-release

Apple security updates addressing actively exploited iOS and macOS vulnerabilities

Updated 3mo agoFirst seen Jan 24, 20269 sources

Apple published multiple security advisories across iOS/iPadOS, macOS, and watchOS releases that include fixes for vulnerabilities reported as actively exploited in the wild. Notable exploited issues include iOS/iPadOS 15.6.1 fixes for kernel and WebKit out-of-bounds writes enabling arbitrary code execution (CVE-2022-32894, CVE-2022-32893), iOS/iPadOS 16.3.1’s exploited WebKit type confusion leading to code execution (CVE-2023-23529), and iOS/iPadOS 15.7.5 plus macOS Big Sur 11.7.6 addressing an IOSurfaceAccelerator out-of-bounds write that could yield kernel-level code execution (CVE-2023-28206) alongside an exploited WebKit use-after-free (CVE-2023-28205). Apple also shipped iOS/iPadOS 16.6.1 and macOS Ventura 13.5.2 updates to remediate an exploited ImageIO buffer overflow (CVE-2023-41064) and an exploited Wallet attachment validation issue that could allow code execution (CVE-2023-41061).

Separately, Apple’s iOS 17.0.1 and watchOS 9.6.3 advisories describe two vulnerabilities (CVE-2023-41991, CVE-2023-41992) reported by Citizen Lab and Google’s Threat Analysis Group as exploited against versions prior to iOS 16.7, involving signature validation bypass and local privilege escalation. Other referenced advisories (e.g., iOS/iPadOS 16.7, iOS/iPadOS 17.2, iOS/iPadOS 18.1, iOS/iPadOS 18.3, macOS Sequoia 15.1, iOS/iPadOS 26.1, macOS Tahoe 26.1, iOS/iPadOS 26.2) primarily enumerate additional CVEs and privacy/logic/memory-safety fixes but do not clearly tie to the same specific exploited-vulnerability disclosures, indicating they are broader platform security bulletins rather than part of a single incident response.

Share:
Apple security updates addressing actively exploited iOS and macOS vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Sep 21, 20233y ago

Apple releases iOS 16.7 with three actively exploited fixes

On 2023-09-21, Apple released iOS 16.7 and iPadOS 16.7, addressing CVE-2023-41992 in the kernel, CVE-2023-41991 in Security, and CVE-2023-41993 in WebKit. Apple said all three flaws may have been actively exploited against iOS versions prior to iOS 16.7.

Apple releases watchOS 9.6.3 for two exploited iOS-related flaws

On 2023-09-21, Apple released watchOS 9.6.3 to fix CVE-2023-41992 and CVE-2023-41991. Apple said both vulnerabilities may have been actively exploited against versions of iOS prior to iOS 16.7.

Sep 7, 20233y ago

Apple releases iOS 16.6.1, iPadOS 16.6.1, and macOS Ventura 13.5.2

On 2023-09-07, Apple shipped iOS 16.6.1, iPadOS 16.6.1, and macOS Ventura 13.5.2 to fix CVE-2023-41064 in ImageIO and a Wallet validation flaw affecting iOS/iPadOS. Apple said the issues may have been actively exploited in the wild, and credited Citizen Lab for assistance and reporting.

Jul 24, 20233y ago

Apple issues iOS 16.6 and iPadOS 16.6 with multiple security fixes

On 2023-07-24, Apple released iOS 16.6 and iPadOS 16.6, fixing numerous vulnerabilities across components including the kernel and WebKit. The advisory notes that at least two of the issues may have been actively exploited, and one flaw, CVE-2023-37450, had first been addressed in Rapid Security Response 16.5.1(c).

Apr 10, 20233y ago

Apple releases macOS Big Sur 11.7.6 for exploited kernel flaw

On 2023-04-10, Apple also released macOS Big Sur 11.7.6 to address CVE-2023-28206, an IOSurfaceAccelerator out-of-bounds write that could let an app execute code with kernel privileges. Apple said it was aware of a report that the issue may have been actively exploited.

Apple releases iOS 15.7.5 and related updates for two exploited flaws

On 2023-04-10, Apple released iOS 15.7.5 and iPadOS 15.7.5 to fix CVE-2023-28206 in IOSurfaceAccelerator and CVE-2023-28205 in WebKit. Apple said both vulnerabilities may have been actively exploited against older iPhone, iPad, and iPod touch devices.

Feb 13, 20233y ago

Apple ships iOS 16.3.1 and iPadOS 16.3.1 with exploited WebKit fix

Apple released iOS 16.3.1 and iPadOS 16.3.1 in February 2023, addressing CVE-2023-23514, CVE-2023-23524, and CVE-2023-23529. Apple noted that the WebKit type confusion flaw CVE-2023-23529 may have been actively exploited.

Aug 17, 20224y ago

Apple releases iOS 15.6.1 and iPadOS 15.6.1 for two zero-days

On 2022-08-17, Apple released iOS 15.6.1 and iPadOS 15.6.1 to fix CVE-2022-32894 in the kernel and CVE-2022-32893 in WebKit. Apple said both flaws may have been actively exploited, allowing kernel-level code execution or code execution via malicious web content.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

86 LINKEDOpen in app
Vulnerabilities
57 linked
Same Origin Policy Bypass in Apple WebKit/SafariKernel use-after-free in Apple operating systemsRoot Privilege Escalation via Path Handling Issue in Apple iOS, iPadOS, macOS, and watchOSSensitive location information disclosure via log redaction issue in Apple iOS/iPadOS/macOSSensitive Location Information Disclosure in Apple iOS, iPadOS, macOS, and watchOSKernel arbitrary code execution in Apple iOS, iPadOS, macOS, and watchOSSensitive location information disclosure via log redaction issue in Apple platformsWebKit arbitrary code execution in Apple platformsKernel arbitrary code execution in Apple operating systemsKernel arbitrary code execution in Apple iOS, iPadOS, and macOSArbitrary JavaScript code execution in macOS VenturaKernel arbitrary code execution in Apple operating systemsDenial-of-service in Apple iOS, iPadOS, and macOSDenial-of-Service Logic Issue in Apple iOS, iPadOS, macOS, and watchOSArbitrary code execution in Apple WebKitArbitrary Code Execution in Apple Web Content ProcessingUse-After-Free in Apple iOS, iPadOS, and macOS KernelCross-Site Scripting in Apple Safari and Apple OS document processingKernel Privilege Arbitrary Code Execution in Apple Neural EngineSensitive location information disclosure via log redaction issue in iOS, iPadOS, and macOSInteger Overflow in LibTIFF TIFFReadRGBATileExtKernel arbitrary code execution in Apple iOS/iPadOS/macOSKernel Use-After-Free in Apple operating systemsKernel arbitrary code execution via integer overflow in Apple iOS, iPadOS, macOS, watchOS, and tvOSSensitive information disclosure in Apple WebKit web content processingSensitive user information tracking issue in Apple Safari and Apple operating systemsArbitrary Code Execution in Apple iOS, iPadOS, macOS, watchOS, and tvOSSensitive location information disclosure via log redaction issue in Apple platformsBuffer Overflow in Apple iOS, iPadOS, macOS, watchOS, and tvOS KernelArbitrary code execution in Apple WebKit web content processingKernel arbitrary code execution in Apple iOS/iPadOS/watchOSArbitrary code execution in Apple WebKitKernel use-after-free in Apple iOS, iPadOS, macOS, tvOS, and watchOSKernel arbitrary code execution in Apple iOS, iPadOS, and macOSArbitrary code execution in Apple Web Content processingSandbox escape in iOS and iPadOS file handling protocolLocation Information Disclosure in macOS VenturaOut-of-bounds Write Kernel Code Execution in Apple iOS, iPadOS, macOS, watchOS, and tvOSWebKit Use-After-Free in Apple Safari, iOS, iPadOS, and macOSPrivilege Elevation in Apple iOS/iPadOS/macOSApple kernel sensitive state modification / PPL bypass in iOS and macOSApple WebKit arbitrary code execution in processing web contentWebKit arbitrary code execution in Apple iOS, iPadOS, macOS, Safari, tvOS, and watchOSSensitive User Data Access in iOS/iPadOS via Environment Variable ValidationKernel Privilege Arbitrary Code Execution in Apple iOS/iPadOS/macOS/watchOS/tvOSApple Security Framework Signature Validation BypassApple Kernel Local Privilege EscalationApple IOSurfaceAccelerator Out-of-Bounds Write Kernel Code ExecutionApple ImageIO Buffer OverflowWebKit Use-After-Free Arbitrary Code ExecutionKernel out-of-bounds write leading to kernel code execution in Apple iOS/iPadOS/macOS (CVE-2022-32894)WebKit Type Confusion Arbitrary Code ExecutionDenial-of-Service via Malicious Certificate in Apple OSesApple Wallet PassKit attachment code executionWebKit arbitrary code execution in Apple Safari and Apple platformsWebKit out-of-bounds write leading to code execution (Apple iOS/iPadOS/macOS/Safari)Apple Kernel Use-After-Free Privilege Escalation
Affected products
10 linked
Ipad MiniWebkitIosIpadIphoneIosIphone 8Ipod TouchMacos VenturaWebkit
Organizations
19 linked
ApplePangu LabGoogleTrend MicroAlibaba CloudTencentSecuRingCross RepublicKasperskyUniversity of ViennaCertiKSTAR Labs SG Pte. LtdComputest Sector 7Ant Security Light-Year LabSuma Soft Pvt. Ltd.KunLun LabCitizen LabAmnesty InternationalThe Citizen Lab at The University of Toronto’s Munk School
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Apple security updates addressing actively exploited iOS and macOS vulnerabilities | Mallory