AVIS DU CERT-FR: Multiple Vulnerabilities in Apple Products

  • Reference: CERTFR-2023-AVI-0806
  • Title: Multiple Vulnerabilities in Apple Products
  • First Version Date: October 5, 2023
  • Last Version Date: October 5, 2023
  • Sources: Apple Security Bulletin HT213961 dated October 4, 2023
  • Attachments: None

Table 1: Document Management Detailed version control is available at the end of this document.

RISKS

  • Privilege Escalation
  • Arbitrary Code Execution

AFFECTED SYSTEMS

  • iOS 17.0.3
  • iPadOS 17.0.3

SUMMARY Multiple vulnerabilities have been discovered in Apple products, enabling an attacker to trigger privilege escalation and execute arbitrary code.

The publisher is aware of a report indicating active exploitation of the vulnerability.

SOLUTION Refer to the publisher’s security bulletin for obtaining patches (see Documentation section).

DOCUMENTATION

  1. Apple Security Bulletin HT213961 dated October 4, 2023
  2. CVE Reference CVE-2023-42824
  3. CVE Reference CVE-2023-5217

https://www.cert.ssi.gouv.fr/avis/CERTFR-2023-AVI-0806/


Posted

in

by

Tags: