ZeroHour

CVE-2023-38606

KEVmass1

Kernel State-Tampering Flaw in Apple iOS, iPadOS, macOS, tvOS and watchOS

CISA: Apple Multiple Products Kernel Unspecified Vulnerability

CVSS 3.1
5.5 medium
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2023-38606 is a kernel vulnerability in Apple's iOS, iPadOS, macOS, tvOS and watchOS, caused by a state-management defect that allowed an app running on the device to modify sensitive kernel state; Apple fixed it with improved state management in its July 2023 updates. Exploitation is local and requires user interaction (a user must run a malicious app), and successful exploitation lets the attacker alter protected kernel state, with the CVSS scoring high integrity impact but no direct confidentiality or availability loss. Apple stated the issue may have been actively exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-07-26; related reporting around this period links 2023 Triangulation-campaign exploit code to recent mass attack activity via the 'Coruna' iOS exploit kit. All users of iPhones, iPads, Macs, Apple TVs and Apple Watches running software older than the July 2023 patched releases (iOS 15.7.8/16.6, iPadOS 15.7.8/16.6, macOS 11.7.9/12.6.8/13.5, tvOS 16.6, watchOS 9.6) are affected.

What to do: Update all affected devices to the patched releases: iOS 16.6 or iOS 15.7.8, iPadOS 16.6 or 15.7.8, macOS Ventura 13.5 / Monterey 12.6.8 / Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6. No workarounds are documented; because the flaw is triggered by apps, users on unpatched devices should avoid installing or running untrusted apps. The CVE is in the CISA KEV catalog (added 2023-07-26), so federal agencies must apply the vendor fixes within the required BOD 22-01 timelines.

Affected
apple iPhone OS (iOS)iOS versions prior to iOS 15.7.8 and iOS 16 versions prior to iOS 16.6 (fixed in iOS 15.7.8 and iOS 16.6)
apple iPadOSiPadOS versions prior to 15.7.8 and iPadOS 16 versions prior to 16.6 (fixed in iPadOS 15.7.8 and iPadOS 16.6)
apple macOS Big Surversions prior to 11.7.9 (fixed in macOS Big Sur 11.7.9)
apple macOS Montereyversions prior to 12.6.8 (fixed in macOS Monterey 12.6.8)
apple macOS Venturaversions prior to 13.5 (fixed in macOS Ventura 13.5)
apple tvOSversions prior to 16.6 (fixed in tvOS 16.6)
apple watchOSversions prior to 9.6 (fixed in watchOS 9.6)
Estimated exposure
mass>1 billion active Apple devices (Apple reported an installed base exceeding 2 billion active devices in 2023) — The flaw spans every major Apple OS line (iPhone, iPad, Mac, Apple TV, Apple Watch), and Apple's disclosed active-device installed base of 2+ billion in 2023 means effectively all unpatched devices are in scope.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, watchos
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news