CVE-2023-41992
Published Sep 21, 2023
Last updated 5 months ago
- Description
- The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7, iOS 16.7 and iPadOS 16.7, macOS Ventura 13.6. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
- Source
- product-security@apple.com
- NVD status
- Analyzed
- Products
- ipados, iphone_os, macos
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Apple Multiple Products Kernel Privilege Escalation Vulnerability
- Exploit added on
- Sep 25, 2023
- Exploit action due
- Oct 16, 2023
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Hype score
- Not currently trending
It's about CVE-2023-41992. 1. trigger the bug on old thread_self 2. trigger ipc_entry_grow_table() in kernel through mach_port_allocate_name() in userspace. 3. call mach_thread_self() again, and it returns a new mach name. WTF...? 🐒 😠 66 https://t.co/fbaCKTGh2q
@KayleejoPe23900
9 Sept 2025
4 Impressions
4 Retweets
5 Likes
8 Bookmarks
9 Replies
0 Quotes
It's about CVE-2023-41992. 1. trigger the bug on old thread_self 2. trigger ipc_entry_grow_table() in kernel through mach_port_allocate_name() in userspace. 3. call mach_thread_self() again, and it returns a new mach name. WTF...?
@WHW_0x455
9 Sept 2025
2827 Impressions
2 Retweets
33 Likes
11 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-30401 2 - CVE-2025-31200 3 - CVE-2025-49704 4 - CVE-2023-41992 5 - CVE-2025-23266 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
28 Jul 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
POC for CVE-2023-41992, a critical iOS kernel vuln patched by Apple in 2023. It affects multiple Apple platforms allowing malicious apps to bypass signature validation & gain elevated privileges. https://t.co/4ki9R9HwhR
@minacrissDev_
26 Jul 2025
1206 Impressions
4 Retweets
33 Likes
4 Bookmarks
0 Replies
0 Quotes
poc for CVE-2023-41992 here. Few people have discussed this vulnerability publicly. iOS kernel vulnerabilities may have entered another era since iOS 16&17 ... https://t.co/4ki9R9HwhR
@minacrissDev_
19 Jul 2025
1196 Impressions
5 Retweets
18 Likes
13 Bookmarks
0 Replies
0 Quotes
POC for CVE-2023-41992, a critical iOS kernel vuln . It affects multiple Apple platforms allowing malicious apps to bypass signature validation & gain elevated privileges. https://t.co/4ki9R9HwhR
@minacrissDev_
12 Jun 2025
1896 Impressions
7 Retweets
15 Likes
8 Bookmarks
0 Replies
0 Quotes
cve-2023-41992 LPE https://t.co/3cIuIRust3
@xcbjkymz
8 Jun 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
cve-2023-41992-test https://t.co/tkAjPkSmED
@xcbjkymz
7 Jun 2025
19 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Drop a poc for CVE-2023-41992 here. Few people have discussed this vulnerability publicly. iOS kernel vulnerabilities may have entered another era since iOS 16&17 ... https://t.co/4ki9R9HwhR
@minacrissDev_
24 May 2025
2392 Impressions
13 Retweets
42 Likes
18 Bookmarks
0 Replies
0 Quotes
Jailbreak news of the week: CVE-2023-41992 PoC shared, Trigon updated, another MacDirtyCow-like bug, & more… https://t.co/eJS1b5VWK8
@iDownloadBlog
18 May 2025
4127 Impressions
0 Retweets
7 Likes
1 Bookmark
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2024-45332 2 - CVE-2025-4427 3 - CVE-2025-47889 4 - CVE-2025-4664 5 - CVE-2023-41992 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
17 May 2025
147 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
POC for CVE-2023-41992, a critical iOS kernel vuln patched by Apple in 2023. It affects multiple Apple platforms allowing malicious apps to bypass signature validation & gain elevated privileges.
@minacrissDev_
16 May 2025
321 Impressions
1 Retweet
3 Likes
2 Bookmarks
0 Replies
0 Quotes
Drop a poc for CVE-2023-41992 here. Few people have discussed this vulnerability publicly. iOS kernel vulnerabilities may have entered another era since iOS 16&17 ... https://t.co/xzWjXrTvzF
@minacrissDev_
15 May 2025
1860 Impressions
3 Retweets
17 Likes
4 Bookmarks
1 Reply
0 Quotes
Security researcher shares PoC for CVE-2023-41992 local privilege escalation bug https://t.co/1gmtuDIpRv
@iDownloadBlog
15 May 2025
2240 Impressions
1 Retweet
6 Likes
1 Bookmark
1 Reply
0 Quotes
Drop a poc for CVE-2023-41992 here. Few people have discussed this vulnerability publicly. iOS kernel vulnerabilities may have entered another era since iOS 16&17 ... https://t.co/9kXfJcFdHA
@WHW_0x455
12 May 2025
290 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1CEB5BA1-7092-4ADE-B19F-FD34CB53CCC3",
"versionEndExcluding": "16.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:ipados:17.0:*:*:*:*:*:*:*",
"matchCriteriaId": "FD0EE39C-DEC4-475C-8661-5BD76457A39E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3FC8EB94-1D4F-4CE8-83D0-9086D1EBBC8F",
"versionEndExcluding": "16.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:*",
"matchCriteriaId": "502CD624-FA22-4C7B-9CA3-53CA938BE1AB",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F05757BB-26B5-40A5-B37C-577706EA11C8",
"versionEndExcluding": "12.7",
"versionStartIncluding": "12.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7A78DA60-AE3B-4B3C-B338-97DAFABEBB1F",
"versionEndExcluding": "13.6",
"versionStartIncluding": "13.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]