{"api_version":"1","generated_at":"2026-04-23T08:14:56+00:00","cve":"CVE-2023-28206","urls":{"html":"https://cve.report/CVE-2023-28206","api":"https://cve.report/api/cve/CVE-2023-28206.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-28206","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-28206"},"summary":{"title":"Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability","description":"An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.","state":"PUBLIC","assigner":"product-security@apple.com","published_at":"2023-04-10 19:15:00","updated_at":"2023-07-27 04:15:00"},"problem_types":["CWE-787"],"metrics":[],"references":[{"url":"https://support.apple.com/en-us/HT213725","name":"https://support.apple.com/en-us/HT213725","refsource":"MISC","tags":["Release Notes"],"title":"About the security content of macOS Big Sur 11.7.6 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://support.apple.com/en-us/HT213724","name":"https://support.apple.com/en-us/HT213724","refsource":"MISC","tags":["Release Notes"],"title":"About the security content of macOS Monterey 12.6.5 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://support.apple.com/en-us/HT213723","name":"https://support.apple.com/en-us/HT213723","refsource":"MISC","tags":["Release Notes"],"title":"About the security content of iOS 15.7.5 and iPadOS 15.7.5 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://support.apple.com/en-us/HT213721","name":"https://support.apple.com/en-us/HT213721","refsource":"MISC","tags":["Release Notes"],"title":"About the security content of macOS Ventura 13.3.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2023/Apr/6","name":"20230410 APPLE-SA-2023-04-10-3 macOS Big Sur 11.7.6","refsource":"FULLDISC","tags":["Mailing List","Release Notes"],"title":"Full Disclosure: APPLE-SA-2023-04-10-3 macOS Big Sur 11.7.6","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://seclists.org/fulldisclosure/2023/Apr/4","name":"20230410 APPLE-SA-2023-04-10-2 macOS Monterey 12.6.5","refsource":"FULLDISC","tags":["Mailing List","Release Notes"],"title":"Full Disclosure: APPLE-SA-2023-04-10-2 macOS Monterey 12.6.5","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://support.apple.com/en-us/HT213720","name":"https://support.apple.com/en-us/HT213720","refsource":"MISC","tags":["Release Notes"],"title":"About the security content of iOS 16.4.1 and iPadOS 16.4.1 - Apple Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2023/Apr/2","name":"20230410 APPLE-SA-2023-04-07-2 macOS Ventura 13.3.1","refsource":"FULLDISC","tags":["Mailing List","Release Notes"],"title":"Full Disclosure: APPLE-SA-2023-04-07-2 macOS Ventura 13.3.1","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://seclists.org/fulldisclosure/2023/Apr/5","name":"20230410 APPLE-SA-2023-04-10-1 iOS 15.7.5 and iPadOS 15.7.5","refsource":"FULLDISC","tags":["Mailing List","Release Notes"],"title":"Full Disclosure: APPLE-SA-2023-04-10-1 iOS 15.7.5 and iPadOS 15.7.5","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://seclists.org/fulldisclosure/2023/Apr/1","name":"20230410 APPLE-SA-2023-04-07-1 iOS 16.4.1 and iPadOS 16.4.1","refsource":"FULLDISC","tags":["Mailing List","Release Notes"],"title":"Full Disclosure: APPLE-SA-2023-04-07-1 iOS 16.4.1 and iPadOS 16.4.1","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-28206","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-28206","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"28206","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"ipados","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"28206","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"iphone_os","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"28206","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"macos","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2023","cve_id":"28206","cve":"CVE-2023-28206","vendorProject":"Apple","product":"iOS, iPadOS, and macOS","vulnerabilityName":"Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability","dateAdded":"2023-04-10","shortDescription":"Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2023-05-01","knownRansomwareCampaignUse":"Unknown","notes":"https://support.apple.com/en-us/HT213720, https://support.apple.com/en-us/HT213721; https://nvd.nist.gov/vuln/detail/CVE-2023-28206","cwes":"CWE-787","catalogVersion":"2026.04.22","updated_at":"2026-04-22 20:03:10"},"epss":{"cve_year":"2023","cve_id":"28206","cve":"CVE-2023-28206","epss":"0.241150000","percentile":"0.960900000","score_date":"2026-04-22","updated_at":"2026-04-23 00:03:16"},"legacy_qids":[{"cve":"CVE-2023-28206","qid":"378364","title":"Apple macOS Ventura 13.3.1 Not Installed (HT213721)"},{"cve":"CVE-2023-28206","qid":"378376","title":"Apple macOS Monterey 12.6.5 Not Installed (HT213724)"},{"cve":"CVE-2023-28206","qid":"378377","title":"Apple macOS Big Sur 11.7.6 Not Installed (HT213725)"},{"cve":"CVE-2023-28206","qid":"610477","title":"Apple iOS 16.4.1 and iPadOS 16.4.1 Security Update Missing (HT213720)"},{"cve":"CVE-2023-28206","qid":"610478","title":"Apple iOS 15.7.5 and iPadOS 15.7.5 Security Update Missing (HT213723)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-28206","ASSIGNER":"product-security@apple.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited."}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Apple","product":{"product_data":[{"product_name":"iOS and iPadOS","version":{"version_data":[{"version_affected":"<","version_name":"unspecified","version_value":"15.7"}]}},{"product_name":"macOS","version":{"version_data":[{"version_affected":"<","version_name":"unspecified","version_value":"11.7"}]}}]}}]}},"references":{"reference_data":[{"url":"https://support.apple.com/en-us/HT213723","refsource":"MISC","name":"https://support.apple.com/en-us/HT213723"},{"url":"https://support.apple.com/en-us/HT213725","refsource":"MISC","name":"https://support.apple.com/en-us/HT213725"},{"url":"https://support.apple.com/en-us/HT213724","refsource":"MISC","name":"https://support.apple.com/en-us/HT213724"},{"url":"https://support.apple.com/en-us/HT213721","refsource":"MISC","name":"https://support.apple.com/en-us/HT213721"},{"url":"https://support.apple.com/en-us/HT213720","refsource":"MISC","name":"https://support.apple.com/en-us/HT213720"}]}},"nvd":{"publishedDate":"2023-04-10 19:15:00","lastModifiedDate":"2023-07-27 04:15:00","problem_types":["CWE-787"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*","versionEndExcluding":"15.7.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionEndExcluding":"15.7.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*","versionStartIncluding":"16.0","versionEndExcluding":"16.4.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*","versionStartIncluding":"16.0","versionEndExcluding":"16.4.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionEndExcluding":"11.7.6","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionStartIncluding":"13.0","versionEndExcluding":"13.3.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionStartIncluding":"12.0","versionEndExcluding":"12.6.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}