CVE-2023-32413

HIGH

iPadOS < 15.7.6 - Race Condition Leading to Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-32413. PoCs published by synacktiv.

AI-analyzed exploit summary This is a functional local privilege escalation (LPE) exploit for CVE-2023-32413, targeting macOS. It leverages a TOCTOU (Time-of-Check to Time-of-Use) vulnerability to overwrite files and achieve root privileges.

Description

A race condition was addressed with improved state handling. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to gain root privileges.

Exploits (1)

nomisec WORKING POC 15 stars
by synacktiv · poc
https://github.com/synacktiv/CVE-2023-32413

This is a functional local privilege escalation (LPE) exploit for CVE-2023-32413, targeting macOS. It leverages a TOCTOU (Time-of-Check to Time-of-Use) vulnerability to overwrite files and achieve root privileges.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: macOS (versions vulnerable to CVE-2023-32413)
No auth needed
Prerequisites: Local access to a vulnerable macOS system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213757
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213758
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213759
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213760
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213761
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213764
Release Notes, Vendor Advisory
https://support.apple.com/en-us/HT213765

Scores

CVSS v3 7.0
EPSS 0.0054
EPSS Percentile 41.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362
Status published
Products (5)
apple/ipados < 15.7.6
apple/iphone_os < 15.7.6
apple/macos 11.0 - 11.7.7
apple/tvos < 16.5
apple/watchos < 9.5
Published Jun 23, 2023
Tracked Since Feb 18, 2026