Cyber Resilience

CVE-2023-42824

Apple Ipados ≤ 16.7.1

CISA KEVActive ExploitationEUVD Exploited
Published
04 October 2023
Modified
05 November 2025
KEV Added
05 October 2023
Patch / advisory
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0094 58th percentile
Risk Priority 83 floored blend · peak EPSS

Summary

CVE-2023-42824 is a high-severity an unspecified weakness vulnerability in Apple Ipados. Its CVSS base score is 7.8 (High).

Operationally, ranked in the top 42% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2023-42824 is a privilege escalation vulnerability in Apple's mobile operating systems that was addressed through improved checks. It affects iOS and iPadOS versions prior to 16.7.1, with a CVSS score of 7.8 reflecting local attack vector, low complexity, and high impact across confidentiality, integrity, and availability.

A local attacker already present on a device can exploit the flaw to elevate privileges. Apple has stated that the issue may have been actively exploited in the wild against versions of iOS before 16.6.

Apple security updates HT213972 and HT213961, along with the corresponding KB articles, direct users to install iOS 16.7.1 and iPadOS 16.7.1 to remediate the issue. The vulnerability is also listed in CISA's catalog of known exploited vulnerabilities.

Apple's disclosure confirms awareness of active exploitation reports against older iOS releases, underscoring the need for prompt patching on supported devices.

EU & UK References

Vulnerability Data

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively…

more

exploited against versions of iOS before iOS 16.6.

CWE(s)
KEV Date Added
05 October 2023

Related Threats

CVEs Like This One

CVE-2021-30983Same product: Apple Ipadosboth on KEV
CVE-2023-41974Same product: Apple Ipadosboth on KEV
CVE-2025-24200Same product: Apple Ipadosboth on KEV
CVE-2022-42827Same product: Apple Ipadosboth on KEV
CVE-2022-22587Same product: Apple Ipadosboth on KEV
CVE-2023-28206Same product: Apple Ipadosboth on KEV
CVE-2020-9907Same product: Apple Ipadosboth on KEV
CVE-2020-9818Same product: Apple Ipadosboth on KEV
CVE-2025-43300Same product: Apple Ipadosboth on KEV
CVE-2023-41991Same product: Apple Ipadosboth on KEV

Affected Assets

apple
ipados
≤ 16.7.1 · 17.0 — 17.0.3
apple
iphone os
≤ 16.7.1 · 17.0 — 17.0.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References