CVE-2023-41061: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Other sources
Apple iOS, iPadOS, and watchOS contain an unspecified vulnerability due to a validation issue affecting Wallet in which a maliciously crafted attachment may result in code execution. This vulnerability was chained with CVE-2023-41064.
— CISA
Wallet. A validation issue was addressed with improved logic.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 9.6.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.6.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.6.1 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 16.6.1 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 16.6.1 - Upgrade
Upgrade
Apple watchOSto a version that resolves this vulnerability.Fixed in 9.6.2 - Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 16.6.1 - Compensating control
Discontinue use of the affected product until the vendor-provided fixes (iOS/iPadOS 16.6.1, watchOS 9.6.2) can be applied if mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2023-41061?
CVE-2023-41061 is a code execution vulnerability in Apple iOS, iPadOS, and watchOS that allows for arbitrary code execution due to a validation issue with attachments.
How severe is CVE-2023-41061?
CVE-2023-41061 has a severity rating of 7.8 out of 10, which is considered high.
Which software versions are affected by CVE-2023-41061?
CVE-2023-41061 affects watchOS versions up to and excluding 9.6.2, iOS versions up to and excluding 16.6.1, and iPadOS versions up to and excluding 16.6.1.
How can I fix CVE-2023-41061?
To fix CVE-2023-41061, update your device to watchOS 9.6.2, iOS 16.6.1, or iPadOS 16.6.1.
Is there any known exploitation of CVE-2023-41061?
Apple is aware of a report that CVE-2023-41061 may have been actively exploited.