CVE-2023-41974: Apple iOS and iPadOS Use-After-Free Vulnerability
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.
Other sources
Accessibility. This issue was addressed with improved redaction of sensitive information.
— Apple
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
— CISA
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Credit
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40529
- CVE-2023-40384
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-42871
- CVE-2023-41071
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-42872
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-32361
- CVE-2023-41232
- CVE-2023-35984
- CVE-2023-41065
- CVE-2023-38596
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-32396
- CVE-2023-41069
- CVE-2023-41980
- CVE-2023-40395
- CVE-2023-40431
- CVE-2023-40391
- CVE-2023-40441
- CVE-2023-40434
- CVE-2023-40396
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41974
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-41060
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-41068
- CVE-2023-41986
- CVE-2023-40401
- CVE-2023-42949
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-42934
- CVE-2023-41063
- CVE-2023-40422
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-40452
- CVE-2023-41070
- CVE-2023-40419
- CVE-2023-40428
- CVE-2023-41968
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-42969
- CVE-2023-42961
- CVE-2023-40393
- CVE-2023-42977
- CVE-2023-42973
- CVE-2023-38614
- CVE-2023-42970
- CVE-2023-42875
- CVE-2024-23222
- CVE-2023-43000
- CVE-2023-43010
Frequently Asked Questions
What is the severity of CVE-2023-41974?
CVE-2023-41974 has a high-severity rating due to its potential to allow arbitrary code execution with kernel privileges.
How do I fix CVE-2023-41974?
To fix CVE-2023-41974, update your device to iOS 17 or iPadOS 17.
Which devices are affected by CVE-2023-41974?
CVE-2023-41974 affects devices running iOS versions up to 17 and iPadOS versions up to 17.
What type of vulnerability is CVE-2023-41974?
CVE-2023-41974 is classified as a use-after-free vulnerability.
What impact does CVE-2023-41974 have on device security?
CVE-2023-41974 could allow an app to execute arbitrary code with elevated privileges, compromising device security.