CVE-2023-41990
KEVmassFont Parsing Code Execution Flaw in Apple iOS, iPadOS, macOS, tvOS, watchOS
CISA: Apple Multiple Products Code Execution Vulnerability
CVE-2023-41990 is a vulnerability in Apple's font processing, addressed via improved handling of caches, in which processing a maliciously crafted font file can lead to arbitrary code execution on the device. It is triggered when an application on the device processes an attacker-supplied font, and the CVSS local/user-interaction vector indicates the target user must be involved (e.g., viewing content that includes the malicious font). A successful exploit gives the attacker arbitrary code execution with high impact on confidentiality, integrity, and availability, and it was used as a component of the sophisticated multi-zero-day Operation Triangulation iPhone attack chain described in recent research. All users of Apple iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions older than the listed fixed releases are affected; Apple stated the issue was actively exploited against versions of iOS released before iOS 15.7.1. Exploitation is confirmed in the wild: CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2024-01-08 (EPSS ~1.3%), and no public proof-of-concept is required given the documented active use.
What to do: Upgrade affected devices to iOS/iPadOS 16.3 (or iOS/iPadOS 15.7.8 for devices remaining on the 15.x line), macOS Ventura 13.2, macOS Monterey 12.6.8, or macOS Big Sur 11.7.9, plus tvOS 16.3 and watchOS 9.3; this is mandatory for U.S. federal agencies per the 2024-01-08 CISA KEV listing. Given the bug's role in the Operation Triangulation campaign, prioritize Apple fleet-wide patching and hunt for indicators of compromise from that campaign on devices that had been running pre-patch versions.
| Apple iOS (iPhone OS) | All versions prior to 16.3; iOS 15.x prior to 15.7.8 (actively exploited against versions before iOS 15.7.1) |
| Apple iPadOS | All versions prior to 16.3; 15.x prior to 15.7.8 |
| Apple macOS Ventura | Prior to 13.2 |
| Apple macOS Monterey | Prior to 12.6.8 |
| Apple macOS Big Sur | Prior to 11.7.9 |
| Apple tvOS | Prior to 16.3 |
| Apple watchOS | Prior to 9.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos, tvos, watchos
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H