CISA Known Exploited Vulnerability

CVE-2023-28206

Apple · iOS, iPadOS, and macOS

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

Date added
BOD 22-01 due date
CWE CWE-787
Ransomware Unknown

CISA description

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.

Required action

Apply updates per vendor instructions.