← Back to browse · API

CVE-2023-41990

Severity
HIGH
CVSS
7.8
EPSS
0.01347
Risk score
56.67
CISA KEV
Yes
PoC
No
Published
2024-01-08
Modified
2024-01-08
First seen
2026-08-07
Aliases
EUVD-2023-46449, GHSA-PC7V-GFWG-HJX7
Products
Apple:Multiple Products, Apple:iOS and iPadOS unspecified <15.7, Apple:iOS and iPadOS unspecified <16.3, Apple:macOS unspecified <11.7, Apple:macOS unspecified <12.6, Apple:macOS unspecified <13.2, Apple:tvOS unspecified <16.3, Apple:watchOS unspecified <9.3
Sources
cisa.gov CVE-2023-41990
euvd EUVD-2023-46449

Description

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability that allows for code execution when processing a font file.

References