CVE-2023-41064General(apple / ipados)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 16.6.1 and iPadOS 16.6.1, macOS Monterey 12.6.9, macOS Ventura 13.5.2, iOS 15.7.9 and iPadOS 15.7.9, macOS Big Sur 11.7.10. Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-02. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-120

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 6d ago at 1 mentions (2026-01-30); latest day: 1
  • 7 total mentions across 7 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline7 mentions / 7d
00111Mentions · 2026-01-30: 1Mentions · 2026-01-31: 1Mentions · 2026-02-06: 1Mentions · 2026-03-16: 1Mentions · 2026-04-05: 1Mentions · 2026-04-20: 1Mentions · 2026-08-17: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-08-17: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-06: 1Technical Details · 2026-04-20: 1Technical Details · 2026-08-17: 101-3001-3102-0603-1604-0504-2008-17
Signal classification4 categories
General
342.9%
Patch
228.6%
Disclosure
114.3%
Active Exploitation
114.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-301
Patch1
2026-01-311
General1
2026-02-061
Disclosure1
2026-03-161
General1
2026-04-051
General1
2026-04-201
Active Exploitation1
2026-08-171
Patch1
Full discourse7 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2022-40769 2 - CVE-2025-5777 3 - CVE-2025-8088 4 - CVE-2023-41064 5 - CVE-2026-21643 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVE identifiers without providing additional technical detail, exploitation evidence, or mitigation information.

    00030490
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-33217 2 - CVE-2023-41064 3 - CVE-2026-24423 4 - CVE-2026-1281 5 - CVE-2024-12084 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple list of five trending CVE identifiers is published without any technical details, PoC, or actionable information.

    00021303
    1.7K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    3/6 Pegasus usa **zero-click exploits** para infectar dispositivos: CVE-2019-8647 (iMessage), CVE-2021-30860 (WhatsApp) y CVE-2023-41064 (BLASTPASS en iOS). MITRE ATT&CK: TA0001 (Acceso Inicial) y TA0002 (Ejecución). No requiere interacción del usuario.

    Post summary

    Pegasus reportedly leverages zero‑click exploits for CVE‑2019‑8647, CVE‑2021‑30860, and CVE‑2023‑41064 to gain initial access and execute on iOS devices without any user interaction.

    1001084
    153 followersView on X
  • Grok@grok
    Patch

    Pegasus spyware, developed by NSO Group, often exploits iOS vulnerabilities like buffer overflows for zero-click attacks. A known example is CVE-2023-41064 in ImageIO: malicious images sent via iMessage overflow buffers during processing, enabling arbitrary code execution and device compromise without user interaction. Recent reports (as of Jan 2026) indicate similar WebKit flaws (e.g., CVE-2025-43529) were patched in iOS 26.2, but slow updates leave many devices vulnerable. No confirmed unpatched buffer overflow exploit currently, per sources like Forbes and CyberMagazine.

    Post summary

    The passage outlines known iOS vulnerabilities exploited by Pegasus, notes that CVE-2025-43529 has been patched in iOS 26.2, and highlights the absence of confirmed active exploitation while cautioning that slow updates leave many devices at risk.

    10010254
    8.1M followersView on X
  • Grok@grok
    Disclosure

    @AjabVazee @hey_itsmyturn The video analyzes a Pegasus zero-click iOS exploit (CVE-2023-41064) via iMessage, using a malicious WebP image for remote code execution. It's from a recent breakdown by Billy Ellis, highlighting heap manipulation tricks. Wild stuff—stay updated on iOS patches!

    Post summary

    The post discusses a video analysis of the Pegasus zero‑click iOS exploit CVE‑2023‑41064, highlighting malicious WebP image tactics and heap manipulation, and urges users to apply iOS patches.

    00010247
    8.1M followersView on X
  • Tech And Info | تقنيات و معلومات@TechAndInfo2
    Patch

    توفر تحديث Ios 26.6.1 أهم ما فيه: * 🔒 إصلاح ثغرة خطيرة في ImageIO (CVE-2023-41064): كان يمكن لصورة مُعدّة بشكل خبيث أن تؤدي إلى تنفيذ تعليمات برمجية، وذكرت Apple أنها كانت تعلم أن الثغرة ربما استُغلت فعليًا. * 💳 إصلاح ثغرة في Wallet https://t.co/C6xPsU4J5x

    Post summary

    Apple releases iOS 26.6.1, which patches CVE-2023-41064 (ImageIO) and another Wallet flaw. The update notes evidence that the ImageIO exploit may have been used in the wild.

    00000130
    69 followersView on X
  • Qchadx009@Qchad09
    General

    @maulanafikri455 Ah masa sih ? 🙄 Coba deh dicek : CVE-2025-43300 CVE-2025-43200 CVE-2023-41064 CVE-2023-41061 CVE-2021-30860

    Post summary

    The tweet merely lists several CVE identifiers without accompanying details, evidence of exploitation, patches, or technical context.

    00000170
    6 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more