ZeroHour

CVE-2023-41974

KEV PoC mass1

Use-After-Free Kernel Code Execution Flaw in Apple iOS and iPadOS

CISA: Apple iOS and iPadOS Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p71
Published
()
KEV added
AI analysis

CVE-2023-41974 is a use-after-free (CWE-416) memory-corruption vulnerability in Apple iOS and iPadOS that was addressed with improved memory management. It is triggered locally when an application on the device exercises the affected code path; the CVSS vector (AV:L/UI:R) indicates the attacker needs code running on the device and user interaction, but no network access or privileges. A successful exploit allows an app to execute arbitrary code with kernel privileges, giving the attacker full control over the affected iPhone or iPad. Anyone running iOS/iPadOS versions prior to iOS 17/iPadOS 17, including legacy 15.x devices prior to 15.8.7, is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, and public references tie it to the spy-grade 'Coruna' iOS exploit kit (23 exploits across five chains) used for financial crime, confirming exploitation in the wild.

What to do: Update iPhones to iOS 17 and iPads to iPadOS 17, or apply the iOS 15.8.7 / iPadOS 15.8.7 emergency updates on legacy hardware that cannot run 17; inventory your fleet for devices on older builds and prioritize them, since the Coruna exploit kit reportedly targets older iOS versions. Until patched, avoid installing apps from untrusted sources, as exploitation requires running a malicious app. Federal agencies must meet the applicable BOD 22-01 required-action deadline for this KEV entry.

Affected
Apple iPhone OS (iOS)iOS versions prior to 17; legacy iOS 15.x prior to 15.8.7 (fixed in iOS 17 and iOS 15.8.7)
Apple iPadOSiPadOS versions prior to 17; legacy iPadOS 15.x prior to 15.8.7 (fixed in iPadOS 17 and iPadOS 15.8.7)
Estimated exposure
mass≈1 billion+ devices in scope — the active iPhone/iPad install base exceeds a billion devices, and the vulnerable set (all builds before iOS/iPadOS 17, plus… — Apple's worldwide active iPhone and iPad install base exceeds one billion devices and the affected range spans all pre-17 and pre-15.8.7 builds, so the vulnerable population is estimated at hundreds of millions to over a billion devices,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.

CISA Known Exploited Vulnerability
Affected
Apple iOS and iPadOS
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news