LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-28206: Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 10, 2023
CVSS 8.6 · High⚠ Actively exploited (CISA KEV)
8.6
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
May 1, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-28206 to its Known Exploited Vulnerabilities catalog on Apr 10, 2023, with a federal patch deadline of May 1, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.5, iOS 16.4.1 and iPadOS 16.4.1, macOS Ventura 13.3.1, iOS 15.7.5 and iPadOS 15.7.5, macOS Big Sur 11.7.6. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVE-2023-28206 is an out-of-bounds write vulnerability in the IOSurfaceAccelerator component of Apple iOS, iPadOS, and macOS. It allows a malicious app to execute code with kernel privileges. This matters because kernel-level access can give an attacker full control over the device, enabling persistence, data theft, or further compromise of the system.

Security and IT teams should treat this as a high-priority issue for Apple device fleets, as successful exploitation bypasses normal app sandboxing and user-level restrictions. Confirm all details, including exact affected builds, against the official Apple security advisory.

How it works

This vulnerability falls under CWE-787 (Out-of-bounds Write). In the IOSurfaceAccelerator component, which handles graphics and surface acceleration tasks, improper bounds checking allows a write operation to target memory outside the intended buffer.

An attacker abuses this by delivering or installing a specially crafted app that interacts with the vulnerable component. The out-of-bounds write can corrupt kernel memory structures, leading to arbitrary code execution with kernel privileges. Public detail on exact trigger conditions or memory layouts is limited; defenders should rely on the vendor advisory rather than assuming specific exploit paths. The result is that a user-space app can escalate to full kernel control without needing additional privileges beyond app installation or execution.

Am I affected? How to find it in your systems

The vulnerability affects Apple iOS, iPadOS, and macOS systems that include the IOSurfaceAccelerator component. These operating systems typically run on iPhones, iPads, Macs, and related Apple hardware managed in enterprise environments via MDM, Apple Business Manager, or manual inventory.

If your environment includes mixed personal and corporate devices, prioritize those with access to sensitive data or networks.

How to remediate

Apply the updates provided by Apple as the primary remediation, following the vendor instructions referenced in CISA guidance. Patch management should target all affected iOS, iPadOS, and macOS devices promptly through MDM push, user notifications, or automated update policies.

Document the update process for compliance and audit purposes.

If you can't patch immediately

When immediate patching is blocked by testing, operational constraints, or device availability, apply compensating controls to reduce exposure until updates can be deployed.

These measures lower but do not eliminate risk; schedule patching as soon as feasible.

If your data may have been exposed

Vulnerabilities that enable kernel code execution can lead to device compromise and subsequent data exposure or lateral movement. Known ransomware use of this specific CVE is not documented. If compromise is suspected, isolate the device, preserve forensic evidence, and investigate for unauthorized access or data exfiltration. Organizations and individuals can run a free exposure scan of their email addresses against known breach datasets to check whether related credentials or personal information appear in public breach records.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS, iPadOS, and macOS
WeaknessCWE-787
CVSS base score8.6 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
PublishedApr 10, 2023
Added to CISA KEVApr 10, 2023
Federal patch deadlineMay 1, 2023
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities