ZeroHour

CVE-2023-41992

KEVmass

Kernel Privilege Escalation in Apple iOS, iPadOS and macOS, Exploited in the Wild

CISA: Apple Multiple Products Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2023-41992 is a kernel privilege escalation flaw in Apple iOS, iPadOS and macOS that Apple fixed with improved checks in iOS 16.7, iPadOS 16.7, macOS Ventura 13.6 and macOS Monterey 12.7. A local attacker who already has some unprivileged access to a device can trigger the flaw to elevate their privileges, gaining high-impact access to confidentiality, integrity and availability (CVSS 7.8, local vector, low privileges, no user interaction). Anyone running affected pre-fix versions of iPhone OS, iPadOS or macOS is exposed; because the vector is local, remote attackers would typically need to chain it with another flaw or gain local access first. Apple reported the issue may have been actively exploited against iOS versions before 16.7, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-25; no public proof-of-concept is known and ransomware use is unconfirmed. Contemporaneous headlines about Predator/Intellexa spyware campaigns suggest targeted spyware operators were among the likely users of this and related Apple zero-days, though the data does not name specific victims for this CVE.

What to do: Upgrade affected devices to iOS 16.7 or later, iPadOS 16.7 or later, macOS Ventura 13.6 or later, or macOS Monterey 12.7 or later, prioritizing iPhones and iPads since the confirmed exploitation targeted pre-16.7 iOS. This satisfies the CISA KEV required action; no workarounds are described, and because exploitation is local, prioritize patching devices used by at-risk or high-value users and check for signs of spyware (e.g., Predator/Intellexa indicators) on devices that are not yet updated.

Affected
Apple iPhone OS (iOS)iOS versions before 16.7 (fixed in 16.7)
Apple iPadOSiPadOS versions before 16.7 (fixed in 16.7)
Apple macOS VenturamacOS Ventura versions before 13.6 (fixed in 13.6)
Apple macOS MontereymacOS Monterey versions before 12.7 (fixed in 12.7)
Estimated exposure
masshundreds of millions of devices (iPhones/iPads/Macs still on pre-fix builds at disclosure) — Apple's active installed base of iPhones, iPads and Macs is on the order of a billion-plus devices, and a substantial share were still running builds earlier than iOS/iPadOS 16.7, macOS Ventura 13.6 or Monterey 12.7 when the patches…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos
Weakness
CWE-754
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news