CVE-2023-38606
Published Jul 27, 2023
Last updated a year ago
- Description
- This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
- Source
- product-security@apple.com
- NVD status
- Analyzed
- Products
- ipados, iphone_os, macos, tvos, watchos
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Apple Multiple Products Kernel Unspecified Vulnerability
- Exploit added on
- Jul 26, 2023
- Exploit action due
- Aug 16, 2023
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Hype score
- Not currently trending
Top 5 Trending CVEs: 1 - CVE-2026-41089 2 - CVE-2023-38606 3 - CVE-2020-17103 4 - CVE-2026-46333 5 - CVE-2026-20182 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
18 May 2026
159 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
TRC analysis reveals the Coruna exploit kit has transitioned from government surveillance tool to widespread cybercriminal weapon targeting iOS devices. Attackers chain CVE-2023-32434 and CVE-2023-38606 to achieve kernel-level compromise and establish persistent C2 channels. This
@aviatrixtrc
27 Mar 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The Coruna iOS exploit kit reuses exploits from Operation Triangulation, including CVE-2023-32434 & CVE-2023-38606. Originally used in targeted espionage, it’s now seen in broader attacks, highlighting the growing proliferation of advanced exploit tools. Read:
@ArmoredMobile
27 Mar 2026
42 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[Securelist] Coruna: the framework used in Operation Triangulation. Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the... https://t.co/PhfzEhsBnN
@shah_sheikh
26 Mar 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
the coruna exploit kit uses undocumented apple chip registers to bypass kernel memory protection. cve-2023-38606 proves that hardware-level "undocumented features" are the ultimate backdoor — lockdown mode is the only software toggle that forces these registers to bail.
@nyakojiru
7 Mar 2026
21 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Coruna : nouveau spyware iOS ciblant iOS, lié à l'Opération Triangulation. Les failles zero-day CVE-2023-32434 & CVE-2023-38606 ont été découvertes par Kaspersky. #Cybersecurity #InfoSec #Vulnerability https://t.co/qzpqJfcK2B
@cyberwatcher_
5 Mar 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2023-41990 2 - CVE-2017-0144 3 - CVE-2025-49144 4 - CVE-2023-38606 5 - CVE-2025-38001 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
20 Oct 2025
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
► Crypto-Anarchist Warning : ► Integrated Circuits Backdoors news : ► Cyber-Barbouzerie "Operation Triangulation" : See page 5 of the PDF below, "The Mystery of CVE-2023-38606" - Operation Triangulation. https://t.co/rTvecrpdOk
@stmanfr
20 Feb 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5E276423-4032-4E12-AB11-88F7047E35EA",
"versionEndExcluding": "15.7.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "33013784-1828-4402-81CF-2794D94A7C48",
"versionEndExcluding": "16.6",
"versionStartIncluding": "16.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8635FA0F-1876-4E3A-B02D-31AEA459C38E",
"versionEndExcluding": "15.7.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4C67BFEB-764A-4C07-A02A-117C6AFAAC6A",
"versionEndExcluding": "16.6",
"versionStartIncluding": "16.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FB5312D6-AEEA-4548-B3EF-B07B46168475",
"versionEndExcluding": "11.7.9",
"versionStartIncluding": "11.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A47C992E-C336-403A-A534-E1A33C7338DE",
"versionEndExcluding": "12.6.8",
"versionStartIncluding": "12.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3D701507-146E-4E5B-8C32-60E797E46627",
"versionEndExcluding": "13.5",
"versionStartIncluding": "13.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "339039D5-7AAC-4252-B4F6-BFCEBB48D92A",
"versionEndExcluding": "16.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "90DFD981-D950-40B0-A699-4878B653A20D",
"versionEndExcluding": "9.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]