Apple Releases Security Updates for Multiple Products
Security updates address two exploited zero-day vulnerabilities affecting multiple Apple products
Summary
Security updates address two exploited zero-day vulnerabilities affecting multiple Apple products
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Apple has released six security updates addressing vulnerabilities in multiple products. Apple are reporting exploitation of an out-of-bounds write vulnerability referred to as CVE-2023-28206 and a use-after-free vulnerability referred to as CVE-2023-28205. These vulnerabilities could allow unauthenticated, remote attackers to execute arbitrary code.
Exploitation of CVE-2023-28206 and CVE-2023-28205
Apple has reported that CVE-2023-28206 and CVE-2023-28205 are being actively exploited. The Cybersecurity and Infrastructure Security Agency (CISA) also added the vulnerabilities to their Known Exploited Vulnerability Catalog.
Remediation advice
Affected organisations are encouraged to review the following Apple security advisories and apply any relevant updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
macOS Monterey 12.6.5 | HT213724 https://support.apple.com/en-gb/HT213724 |
| Patch |
macOS Big Sur 11.7.6 | HT213725 https://support.apple.com/en-gb/HT213725 |
| Patch |
iOS 16.4 and iPadOS 16.4.1 | HT213720 https://support.apple.com/en-gb/HT213720 |
| Patch |
iOS 15.7.5 and iPadOS 15.7.5 | HT213723 https://support.apple.com/en-gb/HT213723 |
| Patch |
Safari 16.4.1 | HT213722 https://support.apple.com/en-gb/HT213722 |
| Patch |
macOS Ventura 13.3.1 | HT213721 https://support.apple.com/en-gb/HT213721 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 11 April 2023 11:43 am