CVE-2023-41061
Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability
A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution.
Apple is aware of a report that this issue may have been actively exploited.
HIGH · CVSS 7.8
⚠ CISA KEV
EPSS 0.01141
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules10
YARA rules0