QID 610521

Date Published: 2023-11-17

QID 610521: Apple iOS 17.1 and iPadOS 17.1 Security Update Missing (HT213982)

iOS is a mobile operating system created and developed by Apple Inc.

Following security issues are observed :
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-41072
The issue was addressed with improved memory handling. CVE-2023-40449
The issue was addressed with improved handling of caches. CVE-2023-40413
The issue was addressed with improved memory handling. CVE-2023-40446
The issue was addressed with improved memory handling. CVE-2023-40416
The issue was addressed with improved memory handling. CVE-2023-40423
The issue was addressed with improved memory handling. CVE-2023-42849
An inconsistent user interface issue was addressed with improved state management. CVE-2023-40408
This issue was addressed by removing the vulnerable code. CVE-2023-42846
A logic issue was addressed with improved checks. CVE-2023-42847
An authentication issue was addressed with improved state management. CVE-2023-42845
The issue was addressed with improved memory handling. CVE-2023-42841
This issue was addressed by restricting options offered on a locked device. CVE-2023-41982
The issue was addressed with improved UI handling. CVE-2023-40445
A privacy issue was addressed with improved private data redaction for log entries. CVE-2023-41254
The issue was addressed with improved memory handling. WebKit Bugzilla
A use-after-free issue was addressed with improved memory management. WebKit Bugzilla
A logic issue was addressed with improved checks. WebKit Bugzilla
The issue was addressed with improved memory handling. WebKit Bugzilla

Affected Devices
iPhone XS and later, iPad Pro 12.9-inch 2nd generation and later, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 6th generation and later, and iPad mini 5th generation and later

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Apple advisory HT213982 for patching details.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT213982 iOS URL Logo support.apple.com/en-in/HT213982