Skip to main content

Apple Releases Security Updates for Multiple Products

Security updates address two exploited zero-day vulnerabilities affecting multiple Apple products

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security updates address two exploited zero-day vulnerabilities affecting multiple Apple products


Threat details

Introduction

Apple has released six security updates addressing vulnerabilities in multiple products. Apple are reporting exploitation of an out-of-bounds write vulnerability referred to as CVE-2023-28206 and a use-after-free vulnerability referred to as CVE-2023-28205. These vulnerabilities could allow unauthenticated, remote attackers to execute arbitrary code.

Exploitation of CVE-2023-28206 and CVE-2023-28205

Apple has reported that CVE-2023-28206 and CVE-2023-28205 are being actively exploited. The Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerabilities to their Known Exploited Vulnerability Catalog. 


Remediation advice

Affected organisations are encouraged to review the following Apple security advisories and apply any relevant updates or workarounds.


Remediation steps

Type Step
Patch

macOS Monterey 12.6.5 | HT213724


https://support.apple.com/en-gb/HT213724
Patch

macOS Big Sur 11.7.6 | HT213725


https://support.apple.com/en-gb/HT213725
Patch

iOS 16.4 and iPadOS 16.4.1 | HT213720


https://support.apple.com/en-gb/HT213720
Patch

iOS 15.7.5 and iPadOS 15.7.5 | HT213723


https://support.apple.com/en-gb/HT213723
Patch

Safari 16.4.1 | HT213722


https://support.apple.com/en-gb/HT213722
Patch

macOS Ventura 13.3.1 | HT213721


https://support.apple.com/en-gb/HT213721


Last edited: 11 April 2023 11:43 am