CVE-2023-38606General(apple / ipados)

MEDIUMCVSS 5.5 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.

4.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-08-16. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 5 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-27); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvoswatchos

Deep dive

Activity timeline11 mentions / 8d
01223Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 3Mentions · 2026-05-17: 1Mentions · 2026-05-18: 1Mentions · 2026-06-15: 1Mentions · 2026-09-10: 1Active Exploitation · 2026-03-27: 2Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-06-15: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-26: 1Technical Details · 2026-05-17: 103-0403-0503-2603-2705-1705-1806-1509-10
Signal classification4 categories
General
545.5%
Disclosure
218.2%
Active Exploitation
218.2%
Patch
218.2%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-042
General2
2026-03-051
Disclosure1
2026-03-261
Disclosure1
2026-03-273
Active Exploitation2General1
2026-05-171
Patch1
2026-05-181
General1
2026-06-151
Patch1
2026-09-101
General1
Full discourse11 posts
  • Sooraj@iAnonymous3000
    Patch

    I think you are referring to Operation Triangulation (CVE-2023-38606). Undocumented MMIO registers in Apple SoCs, patched in iOS 16.6 in 2023. Whether it was a backdoor or abandoned debug hardware is contested, including by the Kaspersky researchers who found it. Citizen Lab and Amnesty Security Lab work with journalists and dissidents facing state actors. They recommend GrapheneOS on Google Pixel, or iPhone with Lockdown Mode.

    Post summary

    CVE-2023-38606 pertains to undocumented MMIO registers in Apple SoCs and was patched in iOS 16.6; there is no indication of active exploitation or a PoC, and the vulnerability is considered mitigated by the patch.

    00041512
    15.0K followersView on X
  • Peter Girnus 🦅@gothburz
    General

    @krykryD @grok Google 'Operation Triangulation' and 'CVE-2023-38606.' The share button already did the declassification.

    Post summary

    The tweet simply references CVE-2023-38606 in the context of Operation Triangulation, without providing any technical, exploit, or remediation details.

    01031760
    120.7K followersView on X
  • 🅾🅼🅰🅼🅾🆁🅸@oMaMoriTTV
    Patch

    @aboo0ood_23 Apple released urgent security updates (addressing CVE-2023-38606 and others) to patch the vulnerabilities and block the exploit completely. The Russian government did ban its officials from using iPhones for official state business, a policy that remains in place.

    Post summary

    The message reports that Apple has issued urgent security updates to patch CVE‑2023‑38606 and related vulnerabilities, effectively blocking the exploit.

    00021545
    281 followersView on X
  • ArmoredMobile@ArmoredMobile
    Active Exploitation

    The Coruna iOS exploit kit reuses exploits from Operation Triangulation, including CVE-2023-32434 & CVE-2023-38606. Originally used in targeted espionage, it’s now seen in broader attacks, highlighting the growing proliferation of advanced exploit tools. Read: https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/ #Coruna #Triangulation #iOS #ZeroDay @ArmoredMobile

    Post summary

    Coruna iOS exploit kit reuses CVE‑2023‑32434 and CVE‑2023‑38606 and has shifted from targeted espionage to being encountered in broader attacks, illustrating real‑world exploitation.

    00030113
    62 followersView on X
  • Peter Girnus 🦅@gothburz
    General

    @NImporteQuiHN @grok Google 'Operation Triangulation' and 'CVE-2023-38606.'

    Post summary

    The tweet references Google’s Operation Triangulation and CVE-2023-38606 but offers no additional detail or actionable information about the vulnerability.

    10020110
    120.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-41089 2 - CVE-2023-38606 3 - CVE-2020-17103 4 - CVE-2026-46333 5 - CVE-2026-20182 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists trending CVEs without providing any technical details, patches, or exploit information.

    00010303
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    General

    『the kernel exploit for CVE-2023-32434 and CVE-2023-38606 vulnerabilities used in Coruna, in fact, is an updated version of the same exploit that had been used in Operation Triangulation.』🧐 Coruna: the framework used in Operation Triangulation https://securelist.com/coruna-framework-updated-operation-triangulation-exploit/119228/

    Post summary

    The note states that the kernel exploits for CVE-2023-32434 and CVE-2023-38606 used in the Coruna framework are updated versions of a prior exploit from Operation Triangulation, offering no further technical or remediation details.

    10000522
    6.8K followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam
    General

    @theXSSrat tutorial hell isn't a knowledge gap. check CVE-2023-38606 for real target paralysis.

    Post summary

    The tweet merely references CVE-2023-38606 without providing any technical details, proof‑of‑concepts, or evidence of exploitation or mitigation. It serves only as a brief mention.

    0000054
    1.3K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals the Coruna exploit kit has transitioned from government surveillance tool to widespread cybercriminal weapon targeting iOS devices. Attackers chain CVE-2023-32434 and CVE-2023-38606 to achieve kernel-level compromise and establish persistent C2 channels. This demonstrates how advanced exploits proliferate across threat actor groups. #ZeroDay #ThreatIntel 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/coruna-exploit-kit-2026

    Post summary

    The post reports that attackers are actively exploiting CVE-2023-32434 and CVE-2023-38606 via the Coruna exploit kit to gain kernel-level control and set up C2 channels on iOS devices.

    00000106
    1.9K followersView on X
  • Shah Sheikh@shah_sheikh
    Disclosure

    [Securelist] Coruna: the framework used in Operation Triangulation. Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the... http://ow.ly/3nj8106wnPa

    Post summary

    Kaspersky analysts report that the Coruna exploit kit includes a kernel exploit targeting CVE-2023-32434 and CVE-2023-38606, used in iPhone attacks.

    0000057
    2.2K followersView on X
  • Cyberwatcher_@cyberwatcher_
    Disclosure

    Coruna : nouveau spyware iOS ciblant iOS, lié à l'Opération Triangulation. Les failles zero-day CVE-2023-32434 & CVE-2023-38606 ont été découvertes par Kaspersky. #Cybersecurity #InfoSec #Vulnerability https://www.undernews.fr/hacking-hacktivisme/espionnage-ios-coruna-les-liens-avec-loperation-triangulation-decryptes-par-kaspersky.html

    Post summary

    Kaspersky announced the discovery of two iOS zero‑day CVEs linked to spyware activity, but no proof‑of‑concept, exploit tool, or remediation details are provided.

    0000029
    12 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplewatchos---

Explore more