Description:
Apple has released iOS 15.8, iOS 16.7.2, iOS 17.1, iPadOS 15.8, iPadOS 16.7.2 and iPadOS 17.1 to fix the vulnerabilities in various Apple devices. The list of vulnerability information can be found at:
https://support.apple.com/en-us/HT213981
https://support.apple.com/en-us/HT213982
https://support.apple.com/en-us/HT213990
Affected Systems:
- iPhone 6s and later, SE (1st generation)
- iPad 5th generation and later, Air 2 and later, mini (4th generation) and later, Pro (all models)
- iPod touch (7th generation)
Impact:
Depending on the vulnerabilities being exploited, a successful exploitation could lead to arbitrary code execution, denial of service, information disclosure or security restriction bypass on an affected device.
Recommendation:
Apple has released new version of iOS and iPadOS to address the issue.
The updates can be obtained through the auto-update mechanism. Users of affected systems should follow the recommendations provided by the product vendor and take immediate actions to mitigate the risk.
More Information:
- https://support.apple.com/en-us/HT213981
- https://support.apple.com/en-us/HT213982
- https://support.apple.com/en-us/HT213990
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32359
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32434
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40408
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40413
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40416
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40423
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40445
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40447
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-40449
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41072
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41254
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41976 (to CVE-2023-41977)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41982 (to CVE-2023-41983)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41988
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41997
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42841
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42845 (to CVE-2023-42847)
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42849
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42852
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42857