High Threat Security Alert (A23-10-05): Multiple Vulnerabilities in Apple iOS and iPadOS
05 October 2023
Apple has released iOS 17.0.3 and iPadOS 17.0.3 to fix the vulnerabilities in various Apple devices. The list of vulnerability information can be found at: https://support.apple.com/en-us/HT213961
Apple has released iOS 16.7.1 and iPadOS 16.7.1 to fix the vulnerabilities in various Apple devices that are unable to update to iOS 17 and iPadOS 17. The details of vulnerability information can be found at: https://support.apple.com/en-us/HT213972
Apple announced that the privilege escalation vulnerability (CVE-2023-42824) has been actively exploited against versions of iOS before iOS 16.6. While Apple released iOS 17.0.3 and iPadOS 17.0.3 on 5 October 2023 to address the issue, Apple has released iOS 16.7.1 and iPadOS 16.7.1 as alternative patches for the devices that are unable to update to iOS 17 and iPadOS 17. Users are advised to take immediate action to patch your affected systems to mitigate the elevated risk of cyber attacks.
iPhone 8 and later
iPad 5th generation and later, Air 3rd generation and later, mini 5th generation and later, Pro (all models)
Depending on the vulnerabilities being exploited, a successful exploitation could lead to arbitrary code execution or privilege escalation on an affected device.
Apple has released new version of iOS and iPadOS to address the issue.
The updates can be obtained through the auto-update mechanism. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.