LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-41974: Apple iOS and iPadOS Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 5, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-41974 to its Known Exploited Vulnerabilities catalog on Mar 5, 2026, with a federal patch deadline of Mar 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.

This vulnerability is a use-after-free flaw in Apple iOS and iPadOS. It could allow an application to execute arbitrary code with kernel-level privileges. The issue matters for organizations managing mobile devices because kernel code execution can lead to full device compromise.

How it works

The weakness is classified as CWE-416, a use-after-free condition. In this class of vulnerability, memory is freed but later accessed, allowing an attacker to manipulate program state.

An attacker may abuse this by crafting input that triggers reuse of freed memory, potentially resulting in arbitrary code execution at the kernel level. Confirm specific mechanics against the vendor advisory.

Am I affected? How to find it in your systems

This affects Apple iOS and iPadOS deployments. Inventory devices running these operating systems and check their versions and configurations.

Signs of exploitation may appear in system logs as unexpected kernel activity or application crashes, though specific indicators should be validated with vendor guidance.

How to remediate

Apply mitigations per vendor instructions. Begin by installing the update referenced in the advisory for the affected operating systems.

If you can't patch immediately

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If your data may have been exposed

Actively exploited vulnerabilities lead to breaches. You can run a free exposure scan of your email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS and iPadOS
WeaknessCWE-416
Added to CISA KEVMar 5, 2026
Federal patch deadlineMar 26, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities