CVE-2023-38136: High severity apple ios, ipados, and watchos vulnerability
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
Other sources
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Apple Neural Engine. The issue was addressed with improved memory handling.
— Apple
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.6 and iPadOS 16.6, watchOS 9.6. An app may be able to execute arbitrary code with kernel privileges.
— MITRE
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-34425
- CVE-2023-38136
- CVE-2023-38580
- CVE-2023-32416
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-36495
- CVE-2023-38604
- CVE-2023-32734
- CVE-2023-32441
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38606
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38572
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38133
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38410
- CVE-2023-38603
- CVE-2023-32437
- CVE-2023-38597
- CVE-2023-40442
- CVE-2023-40439
- CVE-2023-40392
- CVE-2023-40437
- CVE-2022-3970
- CVE-2023-41995
- CVE-2023-40400
- CVE-2023-40394
- CVE-2023-38605
- CVE-2023-40397
- CVE-2023-43000
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-38136.
What is the severity of CVE-2023-38136?
The severity of CVE-2023-38136 is high with a score of 7.8.
How was the issue addressed?
The issue was addressed with improved memory handling.
Which software versions are affected by CVE-2023-38136?
CVE-2023-38136 affects Apple iOS versions up to but not including 16.6, Apple iPadOS versions up to but not including 16.6, and Apple watchOS versions up to but not including 9.6.
How do I fix CVE-2023-38136?
To fix CVE-2023-38136, update your Apple iOS device to version 16.6, update your Apple iPadOS device to version 16.6, and update your Apple watchOS device to version 9.6.