QID 610476

QID 610476: Apple iOS 15.7.4 and iPadOS 15.7.4 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-23541
Multiple validation issues were addressed with improved input sanitization. CVE-2023-27961
The issue was addressed with additional restrictions on the observability of app states. CVE-2023-23543
An out-of-bounds write issue was addressed with improved input validation. CVE-2023-27936
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-23537
The issue was addressed with improved memory handling. CVE-2023-27956
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-27928
An out-of-bounds read was addressed with improved bounds checking. CVE-2023-27946
The issue was addressed with improved memory handling. CVE-2023-23535
A use after free issue was addressed with improved memory management. CVE-2023-27969
An out-of-bounds read was addressed with improved input validation. CVE-2023-27949
The issue was addressed with improved authentication. CVE-2023-28182
The issue was addressed with additional permissions checks. CVE-2023-27963
The issue was addressed by removing origin information. WebKit Bugzilla
A type confusion issue was addressed with improved checks. WebKit Bugzilla

Affected Devices
iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation)

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213673 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213673 iOS URL Logo support.apple.com/en-in/HT213673