← Back to browse · API

CVE-2023-41064

Severity
HIGH
CVSS
7.8
EPSS
0.15263
Risk score
61.54
CISA KEV
Yes
PoC
No
Published
2023-09-07
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2023-45585, GHSA-8C6Q-GXJ3-W77F
Products
Apple:iOS and iPadOS unspecified <15.7, Apple:iOS and iPadOS unspecified <16.6, Apple:iOS, iPadOS, and macOS, Apple:macOS unspecified <11.7, Apple:macOS unspecified <12.6, Apple:macOS unspecified <13.5
Sources
cisa.gov CVE-2023-41064
euvd EUVD-2023-45585

Description

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

References