CVE-2023-41990: Apple Multiple Products Code Execution Vulnerability
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.
Other sources
FontParser. The issue was addressed with improved handling of caches.
— Apple
The issue was addressed with improved handling of caches. This issue is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3. Processing a font file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.7.9 - Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 16.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 9.3 - Upgrade
Upgrade
macOSto a version that resolves this vulnerability.Fixed in 12.6.8 - Upgrade
Upgrade
macOS Venturato a version that resolves this vulnerability.Fixed in 13.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.3 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 15.7.8 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 15.7.8 - Compensating control
Discontinue use of the affected product if vendor mitigations are unavailable.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40442
- CVE-2023-34425
- CVE-2023-32364
- CVE-2023-35983
- CVE-2023-40392
- CVE-2023-34241
- CVE-2023-28319
- CVE-2023-28320
- CVE-2023-28321
- CVE-2023-28322
- CVE-2023-41990
- CVE-2023-36854
- CVE-2023-32418
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38603
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-37285
- CVE-2023-38604
- CVE-2023-38606
- CVE-2023-32441
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-38571
- CVE-2023-29491
- CVE-2023-38601
- CVE-2023-32444
- CVE-2023-2953
- CVE-2023-42829
- CVE-2023-38259
- CVE-2023-38602
- CVE-2023-42831
- CVE-2023-32443
- CVE-2023-42832
- CVE-2023-32422
- CVE-2023-32429
- CVE-2023-1801
- CVE-2023-2426
- CVE-2023-2609
- CVE-2023-2610
- CVE-2023-32438
- CVE-2023-23499
- CVE-2023-23520
- CVE-2023-23519
- CVE-2023-23500
- CVE-2023-23502
- CVE-2023-23504
- CVE-2023-23503
- CVE-2023-23512
- CVE-2023-23511
- CVE-2023-32393
- CVE-2022-0108
- CVE-2023-23496
- CVE-2023-23518
- CVE-2023-23517
- CVE-2023-23505
- CVE-2023-32416
- CVE-2023-36495
- CVE-2023-40440
- CVE-2023-38421
- CVE-2023-38258
- CVE-2023-1916
- CVE-2023-32442
- CVE-2023-38605
- CVE-2022-42915
- CVE-2022-42916
- CVE-2022-32221
- CVE-2022-35260
- CVE-2023-23539
- CVE-2023-23513
- CVE-2023-23493
- CVE-2023-23530
- CVE-2023-23531
- CVE-2023-23507
- CVE-2023-23516
- CVE-2023-23506
- CVE-2023-23498
- CVE-2023-28208
- CVE-2023-23497
- CVE-2023-23510
- CVE-2022-3705
- CVE-2023-23501
- CVE-2023-23508
- CVE-2023-23540
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-37450
- CVE-2023-38572
- CVE-2023-32409
- CVE-2023-38594
- CVE-2023-38597
- CVE-2023-38133
Frequently Asked Questions
What is CVE-2023-41990?
CVE-2023-41990 is a vulnerability that allows processing a font file to lead to arbitrary code execution.
What products are affected by CVE-2023-41990?
iOS, iPadOS, watchOS, tvOS, macOS Ventura, iOS, iPadOS
What is the severity of CVE-2023-41990?
CVE-2023-41990 has a severity rating of 7.8 (high).
How can I fix CVE-2023-41990?
CVE-2023-41990 is fixed in tvOS 16.3, iOS 16.3 and iPadOS 16.3, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Ventura 13.2, watchOS 9.3.
Where can I find more information about CVE-2023-41990?
You can find more information about CVE-2023-41990 at the following references: [Reference 1](https://support.apple.com/en-us/HT213844), [Reference 2](https://support.apple.com/en-us/HT213845), [Reference 3](https://support.apple.com/en-us/HT213842).