CVE-2023-41061: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Credit
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41061?
CVE-2023-41061 is a code execution vulnerability in Apple iOS, iPadOS, and watchOS that allows for arbitrary code execution due to a validation issue with attachments.
How severe is CVE-2023-41061?
CVE-2023-41061 has a severity rating of 7.8 out of 10, which is considered high.
Which software versions are affected by CVE-2023-41061?
CVE-2023-41061 affects watchOS versions up to and excluding 9.6.2, iOS versions up to and excluding 16.6.1, and iPadOS versions up to and excluding 16.6.1.
How can I fix CVE-2023-41061?
To fix CVE-2023-41061, update your device to watchOS 9.6.2, iOS 16.6.1, or iPadOS 16.6.1.
Is there any known exploitation of CVE-2023-41061?
Apple is aware of a report that CVE-2023-41061 may have been actively exploited.