ZeroHour

CVE-2023-42824

KEVmass

Kernel Privilege Escalation in Apple iOS and iPadOS (Actively Exploited)

CISA: Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p59
Published
()
KEV added
AI analysis

CVE-2023-42824 is a privilege escalation vulnerability in the kernel of Apple's iOS and iPadOS, addressed with improved checks in iOS 16.7.1 and iPadOS 16.7.1. It is triggered locally: an attacker who can already run code on the device (for example via a malicious app or as one stage of a chained attack) exploits the flaw to elevate privileges. Successful exploitation grants kernel-level privilege, with high confidentiality, integrity, and availability impact, meaning near-full control of the affected device. Any iPhone or iPad running iOS/iPadOS versions prior to 16.7.1 is affected, and Apple reported the issue was being actively exploited against iOS versions before 16.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-05 with no public PoC listed, making patching urgent.

What to do: Update affected iPhones and iPads to iOS 16.7.1 / iPadOS 16.7.1 or later (any subsequent iOS release includes the fix), and verify device versions via Settings > General > Software Update. There is no indicated workaround, so prioritize patching for high-risk users (executives, admins, journalists), since local kernel elevation bugs of this kind are commonly chained with remote code execution or sandbox-escape exploits. Per CISA's required action, apply the vendor updates promptly or restrict use of unpatched devices.

Affected
Apple iOSversions prior to iOS 16.7.1 (fix released in iOS 16.7.1; exploited in the wild against versions before iOS 16.6)
Apple iPadOSversions prior to iPadOS 16.7.1 (fix released in iPadOS 16.7.1)
Estimated exposure
masshundreds of millions of consumer devices (Apple's active iPhone/iPad installed base exceeds 1 billion) — Apple's publicly reported active installed base of iPhones and iPads is over a billion devices, and even the subset still running iOS/iPadOS versions below 16.7.1 at disclosure plausibly numbers in the hundreds of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6.

CISA Known Exploited Vulnerability
Affected
Apple iOS and iPadOS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news