QID 610498

Date Published: 2023-07-25

QID 610498: Apple iOS 16.6 and iPadOS 16.6 Security Update Missing

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
The issue was addressed with improved memory handling. CVE-2023-38136
A logic issue was addressed with improved restrictions. CVE-2023-32416
The issue was addressed with improved memory handling. CVE-2023-32734
This issue was addressed with improved state management. CVE-2023-38606
A use-after-free issue was addressed with improved memory management. CVE-2023-32381
The issue was addressed with improved checks. CVE-2023-38410
The issue was addressed with improved checks. CVE-2023-38603
A path handling issue was addressed with improved validation. CVE-2023-38565
A logic issue was addressed with improved checks. CVE-2023-38593
The issue was addressed with improvements to the file handling protocol. CVE-2023-32437
The issue was addressed with improved checks. WebKit Bugzilla
The issue was addressed with improved checks. WebKit Bugzilla
The issue was addressed with improved memory handling. WebKit Bugzilla
The issue was addressed with improved checks. WebKit Bugzilla
The issue was addressed with improved checks. WebKit Bugzilla
The issue was addressed with improved checks. WebKit Bugzilla

Affected Devices
iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213841 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213841 iOS URL Logo support.apple.com/en-in/HT213841