QID 610475

Date Published: 2023-04-03

QID 610475: Apple iOS 16.4 and iPadOS 16.4 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-23541
The issue was addressed with improved memory handling. CVE-2023-23540
An out-of-bounds write issue was addressed with improved bounds checking. CVE-2023-27970
This issue was addressed with improved checks. CVE-2023-23532
The issue was addressed with improved checks. CVE-2023-23527
This issue was addressed by removing the vulnerable code. CVE-2023-27931
Multiple validation issues were addressed with improved input sanitization. CVE-2023-27961
The issue was addressed with additional restrictions on the observability of app states. CVE-2023-23543
A buffer overflow was addressed with improved bounds checking. CVE-2023-23494
The issue was addressed with improved checks. CVE-2023-27955
An out-of-bounds read was addressed with improved bounds checking. CVE-2023-23528
The issue was addressed with improved memory handling. CVE-2023-28181
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-23537
The issue was addressed with improved memory handling. CVE-2023-27956
An integer overflow was addressed with improved input validation. CVE-2023-27937
This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. CVE-2023-23526
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-27928
The issue was addressed with improved memory handling. CVE-2023-23535
An out-of-bounds read was addressed with improved input validation. CVE-2023-27929
A use after free issue was addressed with improved memory management. CVE-2023-27969
The issue was addressed with improved memory handling. CVE-2023-27933
This issue was addressed with improved checks. CVE-2023-27943
This issue was addressed with improved checks. CVE-2023-23525
The issue was addressed with improved authentication. CVE-2023-28182
A logic issue was addressed with improved restrictions. CVE-2023-23523
The issue was addressed with improved checks. CVE-2023-27942
The issue was addressed with improved checks. CVE-2023-28194
A logic issue was addressed with improved validation. CVE-2023-28178
The issue was addressed with additional permissions checks. CVE-2023-27963
This issue was addressed by removing the vulnerable code. CVE-2023-27931
This issue was addressed with improved state management. WebKit Bugzilla
The issue was addressed by removing origin information. WebKit Bugzilla

Affected Devices
iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213676 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213676 iOS URL Logo support.apple.com/en-in/HT213676