Vulnerability record · CVE-2023-42824 · published 4 October 2023
CVE-2023-42824: Apple iOS and iPadOS kernel privilege escalation
Apple · Ipados
A kernel flaw in iOS and iPadOS was fixed by improved checks in iOS 16.7.1 and iPadOS 16.7.1. Apple states it is aware of a report that the issue may have been actively exploited against versions before iOS 16.6, so unpatched devices are at risk. The record gives no detail on the vulnerable code path or root cause.
Description
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is confirmed exploited in the wild and in CISA KEV, but requires local access and a foothold, limiting mass remote exploitation.
What it is
A kernel flaw in iOS and iPadOS was fixed by improved checks in iOS 16.7.1 and iPadOS 16.7.1. Apple states it is aware of a report that the issue may have been actively exploited against versions before iOS 16.6, so unpatched devices are at risk. The record gives no detail on the vulnerable code path or root cause.
Impact
A local attacker can elevate privileges to kernel level, gaining high confidentiality, integrity and availability impact on the device.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so an attacker needs code execution or a foothold on the device rather than remote network access.
Exploitation
CVE-2023-42824 is listed in CISA KEV with a 2023-10-26 remediation due date and Apple confirms reports of active exploitation; EPSS 30-day probability is low at roughly 0.9 percent. No ransomware campaign use is documented.
What to do
- Update to iOS 16.7.1 or iPadOS 16.7.1, or a later release, as the vendor fix.
- If immediate patching is not possible, follow CISA KEV guidance to apply vendor mitigations or discontinue use of affected devices.
- Restrict installation of untrusted apps and profiles that could provide the local foothold needed to trigger the flaw.
- Track device fleet patch compliance and prioritize unpatched devices below iOS/iPadOS 16.7.1.
Detection
- Monitor for unexpected privilege escalation or kernel-level anomalies on iOS/iPadOS devices via MDM or endpoint telemetry where available.
- Review device inventory for versions below iOS 16.7.1 and flag them for remediation.
- Watch for exploitation indicators reported by Apple or threat intelligence tied to pre-16.6 iOS versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-42824 to the Known Exploited Vulnerabilities catalog on 5 October 2023 as "Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 26 October 2023.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT213972 | Vendor Advisory |
| https://support.apple.com/en-us/HT213972 | Vendor Advisory |
| https://support.apple.com/kb/HT213961 | Vendor Advisory |
| https://support.apple.com/kb/HT213972 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-42824 | US Government Resource |
Track CVE-2023-42824 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42824), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.