CVE-2023-41061General(apple / ipados)

LOWCVSS 7.8 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-02. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • watchos

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Exploit: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-16); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_oswatchos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-16: 1Mentions · 2026-04-04: 103-1604-04
Signal classification2 categories
General
150.0%
Exploit
150.0%
Classification over time
DateTotalLabels
2026-03-161
General1
2026-04-041
Exploit1
Full discourse2 posts
  • Seven@Seven64939409
    Exploit

    @vonmyhaha @Willem_Lau0 @igeekbb 不是的,是CVE-2023-41064、CVE-2023-41061,这些文件主要由 HTML 和 JavaScript 组成,结构极其简单。 任何人只需复制粘贴,并在几分钟到几小时内将其部署到服务器上即可发起攻击。由于该工具“开箱即用”,即使没有任何 iOS 技术背景的犯罪分子也能轻松上手。

    Post summary

    The post asserts that CVE‑2023‑41064 and CVE‑2023‑41061 can be exploited using ready‑to‑use HTML/JavaScript files that anyone can deploy quickly, implying an available out‑of‑the‑box attack tool.

    00000241
    52 followersView on X
  • Qchadx009@Qchad09
    General

    @maulanafikri455 Ah masa sih ? 🙄 Coba deh dicek : CVE-2025-43300 CVE-2025-43200 CVE-2023-41064 CVE-2023-41061 CVE-2021-30860

    Post summary

    The tweet merely lists five CVE identifiers without any additional context or technical detail.

    00000170
    6 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplewatchos---

Explore more