Record summary

CVE-2023-41990 has a selected CVSS score of 7.8 (high). CISA lists CVE-2023-41990 in KEV.

Description

The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jan 8, 2024 · CISA
VulnCheck KEV
Listed · Jan 23, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 5, 2024 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListBefore 16.3affected
Before 15.7affected
CVE ListBefore 11.7affected
Before 13.2affected
Before 12.6affected
CVE ListBefore 16.3affected
CVE ListBefore 9.3affected

References

9