Vulnerability record · CVE-2023-28206 · published 10 April 2023
CVE-2023-28206: Apple iOS, iPadOS and macOS out-of-bounds write in IOSurfaceAccelerator
Apple · Ipados
An out-of-bounds write in Apple's IOSurfaceAccelerator component was fixed with improved input validation in macOS Monterey 12.6.5, macOS Ventura 13.3.1, macOS Big Sur 11.7.6, iOS 16.4.1/iPadOS 16.4.1 and iOS 15.7.5/iPadOS 15.7.5. Apple states it is aware of a report that this issue may have been actively exploited, so unpatched Apple devices are at real risk.
Description
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high CVSS score, but exploitation requires a local malicious app plus user interaction, which limits mass remote abuse.
What it is
An out-of-bounds write in Apple's IOSurfaceAccelerator component was fixed with improved input validation in macOS Monterey 12.6.5, macOS Ventura 13.3.1, macOS Big Sur 11.7.6, iOS 16.4.1/iPadOS 16.4.1 and iOS 15.7.5/iPadOS 15.7.5. Apple states it is aware of a report that this issue may have been actively exploited, so unpatched Apple devices are at real risk.
Impact
A malicious app can execute arbitrary code with kernel privileges, giving the attacker full control of the affected device. This is a local privilege escalation to the highest privilege level on the platform.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the attacker must get a malicious app running on the device and convince the user to trigger it. It is not remotely reachable without that local foothold and user action.
Exploitation
CVE-2023-28206 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-10, due 2023-05-01) and Apple states it may have been actively exploited; EPSS 30-day probability is 0.22967 (97.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the Apple updates that fix this issue: macOS Ventura 13.3.1, macOS Monterey 12.6.5, macOS Big Sur 11.7.6, iOS/iPadOS 16.4.1 and iOS/iPadOS 15.7.5.
- Prioritize patching internet-facing and executive/high-value Apple devices first, per the CISA KEV due date of 2023-05-01.
- Enforce a minimum OS version policy for Apple endpoints and block or flag devices below the fixed versions.
- Restrict users from installing untrusted or sideloaded apps, since exploitation requires a malicious app and user interaction.
- Verify patch compliance across iPhone, iPad and Mac fleets and re-check devices that were offline during the patch window.
Detection
- Inventory Apple endpoints and report any running macOS, iOS or iPadOS versions below the fixed releases listed in the Apple advisories.
- Monitor for unexpected kernel-level crashes or panics on Apple devices, which can accompany out-of-bounds write exploitation.
- Alert on installation or execution of unsigned, sideloaded or otherwise untrusted apps on managed Apple devices.
- Correlate endpoint telemetry for suspicious app behavior immediately preceding kernel panics or privilege escalation events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-28206 to the Known Exploited Vulnerabilities catalog on 10 April 2023 as "Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 1 May 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT213720 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213721 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213723 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213724 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213725 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213720 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213721 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213723 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213724 | Release NotesVendor Advisory |
| https://support.apple.com/en-us/HT213725 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-28206 | US Government Resource |
Track CVE-2023-28206 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28206), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.