CVE-2023-32434
KEVmassInteger Overflow in Apple iOS, iPadOS, macOS and watchOS Grants Kernel-Privilege Code Execution
CISA: Apple Multiple Products Integer Overflow Vulnerability
CVE-2023-32434 is an integer overflow (CWE-190) in a kernel component of Apple's operating systems, caused by insufficient input validation. It is triggered when a malicious or compromised app processes input that overflows an integer value, allowing the attacker's code to escape the app sandbox. Successful exploitation lets an app execute arbitrary code with kernel privileges, the highest level of access on the device, giving full control of the affected iPhone, iPad, Mac or Apple Watch. All devices running iOS/iPadOS before 16.5.1 (or 15.7.7 on the iOS 15 branch), macOS Ventura before 13.4.1, macOS Monterey before 12.6.7, macOS Big Sur before 11.7.8, or watchOS before 9.5.2 (or 8.8.1) are affected, which spans Apple's entire device ecosystem. Exploitation is confirmed in the wild: Apple reported the flaw was actively exploited against iOS versions released before iOS 15.7, CISA added it to the KEV catalog on 2023-06-23, and news reports link it to the Operation Triangulation spyware campaign and commercial iOS exploit kits.
What to do: Immediately update devices: iOS/iPadOS 16.5.1 (or iOS/iPadOS 15.7.7 for older models), macOS Ventura 13.4.1, Monterey 12.6.7, or Big Sur 11.7.8, and watchOS 9.5.2 (or watchOS 8.8.1 for older models), per the CISA KEV required action. Use MDM or device inventories to confirm fleet-wide patch compliance, prioritizing externally used and executive devices. Until patched, have users avoid installing or opening untrusted apps, since exploitation requires a local app as the delivery vector.
| Apple iOS | All versions prior to 16.5.1; iOS 15.x prior to 15.7.7 |
| Apple iPadOS | All versions prior to 16.5.1; iPadOS 15.x prior to 15.7.7 |
| Apple macOS (Ventura) | Prior to 13.4.1 |
| Apple macOS (Monterey) | Prior to 12.6.7 |
| Apple macOS (Big Sur) | Prior to 11.7.8 |
| Apple watchOS | All versions prior to 9.5.2; watchOS 8.x prior to 8.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos, watchos
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H