CVE-2023-41974
9.5 CISA KEVApple · iOS and iPadOS
A use-after-free vulnerability in Apple iOS and iPadOS allows an application to execute arbitrary code with kernel privileges.
Executive summary
This critical use-after-free vulnerability in Apple iOS and iPadOS is confirmed to be actively exploited in the wild and enables attackers to gain kernel-level code execution.
Vulnerability
This is a use-after-free memory management vulnerability that occurs within the kernel. It allows a malicious application to achieve arbitrary code execution with kernel privileges, effectively bypassing standard iOS sandbox security boundaries.
Business impact
The severity of this vulnerability is underscored by its 9.5 CVSS score, reflecting its potential for total system compromise. Successful exploitation grants an attacker full kernel-level access, which can lead to complete data exfiltration, unauthorized surveillance, and the circumvention of all device security controls. Given its inclusion in the CISA Known Exploited Vulnerabilities catalog and association with the Coruna exploit kit, the risk to organizational data and privacy is extreme.
Remediation
Immediate Action: Update all affected devices to iOS 17 or iPadOS 17, or to version 15.8.7 for older devices, as these versions contain the necessary memory management fixes.
Proactive Monitoring: Monitor device management logs for unusual application behavior or unexpected privilege escalation attempts that may indicate an exploit attempt.
Compensating Controls: Ensure that mobile device management (MDM) policies restrict the installation of untrusted or unauthorized applications, as this vulnerability typically requires an application to be present on the device to initiate the exploit.
Exploitation status
Public Exploit Available: Yes, public proof-of-concept code is available on GitHub and the vulnerability is associated with the Coruna exploit kit.
Analyst recommendation
Due to the confirmed active exploitation and the high level of access granted to an attacker, this vulnerability presents an immediate and severe threat to organizational security. Administrators must prioritize the deployment of the specified updates to all managed Apple devices to mitigate the risk of kernel-level exploitation and potential compromise.