ZeroHour

CVE-2023-41990

KEVmass

Font Parsing Code Execution Flaw in Apple iOS, iPadOS, macOS, tvOS, watchOS

CISA: Apple Multiple Products Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p71
Published
()
KEV added
AI analysis

CVE-2023-41990 is a vulnerability in Apple's font processing, addressed via improved handling of caches, in which processing a maliciously crafted font file can lead to arbitrary code execution on the device. It is triggered when an application on the device processes an attacker-supplied font, and the CVSS local/user-interaction vector indicates the target user must be involved (e.g., viewing content that includes the malicious font). A successful exploit gives the attacker arbitrary code execution with high impact on confidentiality, integrity, and availability, and it was used as a component of the sophisticated multi-zero-day Operation Triangulation iPhone attack chain described in recent research. All users of Apple iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions older than the listed fixed releases are affected; Apple stated the issue was actively exploited against versions of iOS released before iOS 15.7.1. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-01-08 (EPSS ~1.3%), and no public proof-of-concept is required given the documented active use.

What to do: Upgrade affected devices to iOS/iPadOS 16.3 (or iOS/iPadOS 15.7.8 for devices remaining on the 15.x line), macOS Ventura 13.2, macOS Monterey 12.6.8, or macOS Big Sur 11.7.9, plus tvOS 16.3 and watchOS 9.3; this is mandatory for U.S. federal agencies per the 2024-01-08 CISA KEV listing. Given the bug's role in the Operation Triangulation campaign, prioritize Apple fleet-wide patching and hunt for indicators of compromise from that campaign on devices that had been running pre-patch versions.

Affected
Apple iOS (iPhone OS)All versions prior to 16.3; iOS 15.x prior to 15.7.8 (actively exploited against versions before iOS 15.7.1)
Apple iPadOSAll versions prior to 16.3; 15.x prior to 15.7.8
Apple macOS VenturaPrior to 13.2
Apple macOS MontereyPrior to 12.6.8
Apple macOS Big SurPrior to 11.7.9
Apple tvOSPrior to 16.3
Apple watchOSPrior to 9.3
Estimated exposure
masson the order of 1 billion+ Apple devices (Apple has publicly reported over 2 billion active devices across these product lines) — Estimate based on Apple's publicly reported installed base of more than 2 billion active devices spanning iPhone, iPad, Mac, Apple Watch, and Apple TV, with older iPhone hardware capped on the iOS 15.x line that only received the fix in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, watchos
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news