CVE-2023-28185

MEDIUM

iPadOS 15.0-15.7.4 - Denial of Service via Integer Overflow

Title source: llm
STIX 2.1

Description

An integer overflow was addressed through improved input validation. This issue is fixed in tvOS 16.4, macOS Big Sur 11.7.5, iOS 16.4 and iPadOS 16.4, watchOS 9.4, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. An app may be able to cause a denial-of-service.

References (6)

Core 6
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213673
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213674
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213675
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213676
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213677
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213678

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 10.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-190
Status published
Products (5)
apple/ipados 15.0 - 15.7.4
apple/iphone_os 15.0 - 15.7.4
apple/macos 11.0 - 11.7.5
apple/tvos < 16.4
apple/watchos < 9.4
Published Jan 10, 2024
Tracked Since Feb 18, 2026