CVE-2023-41992
KEVmassKernel Privilege Escalation in Apple iOS, iPadOS and macOS, Exploited in the Wild
CISA: Apple Multiple Products Kernel Privilege Escalation Vulnerability
CVE-2023-41992 is a kernel privilege escalation flaw in Apple iOS, iPadOS and macOS that Apple fixed with improved checks in iOS 16.7, iPadOS 16.7, macOS Ventura 13.6 and macOS Monterey 12.7. A local attacker who already has some unprivileged access to a device can trigger the flaw to elevate their privileges, gaining high-impact access to confidentiality, integrity and availability (CVSS 7.8, local vector, low privileges, no user interaction). Anyone running affected pre-fix versions of iPhone OS, iPadOS or macOS is exposed; because the vector is local, remote attackers would typically need to chain it with another flaw or gain local access first. Apple reported the issue may have been actively exploited against iOS versions before 16.7, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-25; no public proof-of-concept is known and ransomware use is unconfirmed. Contemporaneous headlines about Predator/Intellexa spyware campaigns suggest targeted spyware operators were among the likely users of this and related Apple zero-days, though the data does not name specific victims for this CVE.
What to do: Upgrade affected devices to iOS 16.7 or later, iPadOS 16.7 or later, macOS Ventura 13.6 or later, or macOS Monterey 12.7 or later, prioritizing iPhones and iPads since the confirmed exploitation targeted pre-16.7 iOS. This satisfies the CISA KEV required action; no workarounds are described, and because exploitation is local, prioritize patching devices used by at-risk or high-value users and check for signs of spyware (e.g., Predator/Intellexa indicators) on devices that are not yet updated.
| Apple iPhone OS (iOS) | iOS versions before 16.7 (fixed in 16.7) |
| Apple iPadOS | iPadOS versions before 16.7 (fixed in 16.7) |
| Apple macOS Ventura | macOS Ventura versions before 13.6 (fixed in 13.6) |
| Apple macOS Monterey | macOS Monterey versions before 12.7 (fixed in 12.7) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos
- Weakness
- CWE-754
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H