NVD disclosure day

Published threat advisories for September 21, 2023

CVE advisoryKnown Exploit

CVE-2023-41993

Apple WebKit Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability exists in Apple software that allows for arbitrary code execution through the processing of web content. This poses a risk to affected systems and data. <hr/> A vulnerability in Apple software allows for arbitrary code execution when processing web content, potentially impacting systems and data. <hr/>

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-41992

Apple macOS and iOS Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability affects Apple's macOS, iOS, and iPadOS operating systems. It allows a local attacker to elevate their privileges, which could lead to unauthorized access to sensitive data and system functions. The vulnerability has been reported as actively exploited against earlier versions of iOS, posing a realist

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-41991

Apple OS: Malicious App Can Bypass Signature Validation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A certificate validation issue in Apple operating systems may allow a malicious application to bypass signature validation. This could impact the integrity of software on affected devices and poses a potential risk to systems and data. Apple has released updates to address this vulnerability.

• CISA KEV