CVE-2023-41995: Use After Free
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Accessibility. This issue was addressed with improved redaction of sensitive information.
— Apple
Accounts. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Airport. A permissions issue was addressed with improved redaction of sensitive information.
— Apple
AMD. A buffer overflow issue was addressed with improved memory handling.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-40384
- CVE-2023-32377
- CVE-2023-38615
- CVE-2023-40448
- CVE-2023-40432
- CVE-2023-42871
- CVE-2023-40399
- CVE-2023-40410
- CVE-2023-42872
- CVE-2023-42929
- CVE-2023-42925
- CVE-2023-38612
- CVE-2023-32361
- CVE-2023-35984
- CVE-2023-40402
- CVE-2023-40426
- CVE-2023-42876
- CVE-2023-41065
- CVE-2023-29497
- CVE-2023-38596
- CVE-2023-42943
- CVE-2023-40406
- CVE-2023-40420
- CVE-2023-40528
- CVE-2023-40438
- CVE-2023-41994
- CVE-2023-40407
- CVE-2023-32396
- CVE-2023-42933
- CVE-2023-41980
- CVE-2023-40411
- CVE-2023-40395
- CVE-2023-40391
- CVE-2023-40441
- CVE-2023-42959
- CVE-2023-23495
- CVE-2023-40434
- CVE-2023-38586
- CVE-2023-40436
- CVE-2023-40396
- CVE-2023-41995
- CVE-2023-42870
- CVE-2023-41981
- CVE-2023-41984
- CVE-2023-40429
- CVE-2023-41060
- CVE-2023-41067
- CVE-2023-40400
- CVE-2023-40454
- CVE-2023-41073
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-42957
- CVE-2023-32421
- CVE-2023-42826
- CVE-2023-42918
- CVE-2023-41986
- CVE-2023-40455
- CVE-2023-40386
- CVE-2023-38408
- CVE-2023-40401
- CVE-2023-40393
- CVE-2023-42949
- CVE-2023-42934
- CVE-2023-37448
- CVE-2023-38607
- CVE-2023-41987
- CVE-2023-41063
- CVE-2023-40422
- CVE-2023-39233
- CVE-2023-40388
- CVE-2023-35990
- CVE-2023-40417
- CVE-2023-40452
- CVE-2023-40430
- CVE-2023-41996
- CVE-2023-41078
- CVE-2023-41070
- CVE-2023-40541
- CVE-2023-41079
- CVE-2023-40443
- CVE-2023-41968
- CVE-2023-40450
- CVE-2023-42948
- CVE-2023-40424
- CVE-2023-39434
- CVE-2023-40414
- CVE-2023-41074
- CVE-2023-35074
- CVE-2023-41993
- CVE-2023-32359
- CVE-2023-40385
- CVE-2023-42833
- CVE-2023-38610
- CVE-2023-41066
- CVE-2023-41979
- CVE-2023-40442
- CVE-2023-40439
- CVE-2023-34425
- CVE-2023-38136
- CVE-2023-38580
- CVE-2023-40392
- CVE-2023-40437
- CVE-2023-32416
- CVE-2022-3970
- CVE-2023-38590
- CVE-2023-38598
- CVE-2023-36495
- CVE-2023-38604
- CVE-2023-32734
- CVE-2023-32441
- CVE-2023-38261
- CVE-2023-38424
- CVE-2023-38425
- CVE-2023-38606
- CVE-2023-32381
- CVE-2023-32433
- CVE-2023-35993
- CVE-2023-38410
- CVE-2023-38603
- CVE-2023-38565
- CVE-2023-38593
- CVE-2023-40394
- CVE-2023-32437
- CVE-2023-38605
- CVE-2023-40397
- CVE-2023-38599
- CVE-2023-32445
- CVE-2023-38592
- CVE-2023-38572
- CVE-2023-38594
- CVE-2023-38595
- CVE-2023-38600
- CVE-2023-38611
- CVE-2023-37450
- CVE-2023-42866
- CVE-2023-38597
- CVE-2023-38133
- CVE-2023-40529
- CVE-2023-41174
- CVE-2023-40409
- CVE-2023-40412
- CVE-2023-41071
- CVE-2023-41232
- CVE-2023-41069
- CVE-2023-40431
- CVE-2023-41974
- CVE-2023-41068
- CVE-2023-40456
- CVE-2023-40520
- CVE-2023-40419
- CVE-2023-40428
- CVE-2023-42969
- CVE-2023-42961
- CVE-2023-42977
- CVE-2023-42973
- CVE-2023-38614
- CVE-2023-42970
- CVE-2023-42875
- CVE-2023-41077
- CVE-2023-42981
- CVE-2023-42982
- CVE-2023-42983
- CVE-2023-40425
- CVE-2023-41076
- CVE-2023-43000
Frequently Asked Questions
What is CVE-2023-41995?
CVE-2023-41995 is a use-after-free vulnerability in the Kernel that has been addressed with improved memory management.
What is the severity of CVE-2023-41995?
The severity of CVE-2023-41995 is not mentioned.
Which software products are affected by CVE-2023-41995?
CVE-2023-41995 affects Apple iOS (up to version 17), Apple iPadOS (up to version 17), and Apple macOS Sonoma (up to version 14).
How can I fix CVE-2023-41995?
To fix CVE-2023-41995, update your Apple device to the latest version of the affected software, as mentioned in the Apple support documents: [link1](https://support.apple.com/en-us/HT213940) and [link2](https://support.apple.com/en-us/HT213938).
What is CWE-416?
CWE-416 is a use-after-free vulnerability that occurs when an object is accessed after it has been freed from memory.