CVE-2023-41974Active Exploitation(apple / ipados)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kernel privileges.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 10 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 9 signals
  • Disclosure: 2 classified signals
  • Peaked 8d ago at 6 mentions (2026-03-06); latest day: 1
  • 19 total mentions across 10 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline19 mentions / 10d
02356Mentions · 2026-03-05: 3Mentions · 2026-03-06: 6Mentions · 2026-03-09: 1Mentions · 2026-03-11: 2Mentions · 2026-03-12: 2Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-27: 1Mentions · 2026-09-20: 1PoC Mentioned / Linked · 2026-09-20: 1Exploit Tool / Code · 2026-03-06: 1Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-09-20: 1Active Exploitation · 2026-03-05: 2Active Exploitation · 2026-03-06: 4Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-11: 2Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-27: 1Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-11: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-27: 103-0503-0603-0903-1103-1203-1403-1603-1703-2709-20
Signal classification5 categories
Active Exploitation
947.4%
Patch
631.6%
Disclosure
210.5%
General
15.3%
Exploit
15.3%
Referenced assets23 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-053
Active Exploitation2Disclosure1
2026-03-066
Active Exploitation2Disclosure1General1Patch2
2026-03-091
Patch1
2026-03-112
Active Exploitation2
2026-03-122
Patch2
2026-03-141
Patch1
2026-03-161
Active Exploitation1
2026-03-171
Active Exploitation1
2026-03-271
Active Exploitation1
2026-09-201
Exploit1
Full discourse19 posts
  • Alfie@alfiecg_dev
    Exploit

    @WHW_0x455 street_race: CVE-2020-9859 (AKA tachy0n or lightspeed) busy_schedule: CVE-2020-27905 & CVE-2020-9964 (AKA oob_events) dangling_join: CVE-2021-30937 (AKA multicast_bytecopy) madvm: CVE-2023-41974 (AKA kfd landa)

    Post summary

    The tweet maps four CVE identifiers to their corresponding exploit/PoC codenames (street_race, busy_schedule, dangling_join, madvm), signaling the existence and availability of named exploit tools for these vulnerabilities.

    1101861.8K
    8.7K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに5件の脆弱性を追加。ハイクビジョンのCVE-2017-7921、Rockwell Automation製品のCVE-2021-22681、Apple製品のCVE-2021-30952、CVE-2023-41974、CVE-2023-43000。 https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA added five CVEs to its catalog of known exploited vulnerabilities, confirming active exploitation in the wild.

    10021821
    7.3K followersView on X
  • piyokango@piyokango
    Patch

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/5追加) 🛡️No.1533 CVE-2017-7921 Hikvision Multiple Products Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上で特権昇格を行う恐れがあります。また脆弱性の悪用により、機密情報にアクセスされる可能性があります。 https://www.hikvision.com/us-en/support/document-center/special-notices/privilege-escalating-vulnerability-in-certain-hikvision-ip-cameras/ 🛡️No.1534 CVE-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:認証情報の不十分な保護 (CWE-522 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、Studio 5000 Logix Designerソフトウェアにおいて、キーが発見される恐れがあります。このキーは、LogixコントローラがRockwell Automationの設計ソフトウェアと通信していることを確認するために使用されます。この脆弱性が悪用されると、不正なアプリケーションがLogixコントローラに接続できるようになる可能性があります。この脆弱性を悪用するには、不正なユーザーがコントローラへのネットワークアクセスが必要になります。 https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 🛡️No.1535 CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:整数オーバーフローまたはラップアラウンド (CWE-190 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT212975 https://support.apple.com/en-us/HT212976 https://support.apple.com/en-us/HT212978 https://support.apple.com/en-us/HT212980 https://support.apple.com/en-us/HT212982 🛡️No.1536 CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: アプリを介して、カーネル権限で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT213938 https://support.apple.com/kb/HT213938 🛡️No.1537 CVE-2023-43000 Apple Multiple products Use-After-Free Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、メモリ破損が発生する恐れがあります。 https://support.apple.com/en-us/120324 https://support.apple.com/en-us/120331 https://support.apple.com/en-us/120338 CISA Adds Five Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added five known exploited vulnerabilities to its catalog, detailing CVEs, severity levels, and providing vendor mitigation links that confirm the availability of patches or workarounds.

    010203.5K
    42.6K followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨Cisco Catalyst SD-WANの脆弱性、さらに2件の悪用が明らかに:CVE-2026-20128、CVE-2026-20122 ⚠️米CISA、Apple製品の古い脆弱性3件をKEVカタログに追加(CVE-2023-43000、CVE-2021-30952、CVE-2023-41974) 〜サイバーアラート3月6日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44386/

    Post summary

    The post announces that the Cisco Catalyst SD‑WAN CVEs are being actively exploited and notes that CISA has added certain older Apple CVEs to its KEV catalog.

    01010195
    1.2K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    The Coruna iOS exploit kit combines WebKit vulnerabilities with kernel exploits to achieve full device compromise. Attackers chain CVE-2023-41974 and CVE-2021-30952 for zero-click attacks via iMessage, then move laterally within devices to exfiltrate financial data and personal media. #MobileSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/coruna-ios-exploit-kit-2026-mass-attacks

    Post summary

    The post details that the Coruna iOS exploit kit chains WebKit and kernel CVEs (CVE-2023-41974 and CVE-2021-30952) to execute zero‑click iMessage attacks and laterally exfiltrate data.

    00001149
    1.9K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/03/05:Apple macOS/iOS などにおける複数の脆弱性を登録 https://iototsecnews.jp/2026/03/09/cisa-warns-of-macos-and-ios-vulnerabilities-exploited-in-attacks/ Apple の製品群で発見された深刻な脆弱性は、主にメモリ管理と計算処理の不備に起因するものです。具体的には、CVE-2023-43000/CVE-2023-41974 におけるメモリ解放後使用の問題と、CVE-2021-30952 における整数オーバーフローの問題です。メモリ解放後使用とは、プログラムが再割り当て済みのメモリを参照し続けることで不正なコード実行を許すものであり、整数オーバーフローは、数値計算の結果が記憶領域の上限を超えてしまうものです。これらの脆弱性を悪用する攻撃者は、悪意の Web コンテンツを介して、カーネル権限でのコード実行などを引きこす恐れがあります。確実な更新適用で保護できますので、早めの対応が推奨されます。 #Apple #CISA #CVE202130952 #CVE202341974 #CVE202343000 #Exploit #Government #iOS #KEV #macOS #Vulnerability

    Post summary

    The text reports that Apple’s macOS and iOS are affected by CVE-2023-43000, CVE-2023-41974, and CVE-2021-30952, which enable memory‑use‑after‑free and integer overflow attacks that could lead to kernel‑privilege code execution, and that applying updates is recommended to mitigate the risks. The Kev warning implies active exploitation in the wild.

    01000143
    484 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Apple has released security patches for older iPhones and iPads to fix kernel and WebKit vulnerabilities exploited by the Coruna exploit kit, addressing multiple CVEs including CVE-2023-41974 and CVE-2024-23222. #Coruna #ExploitPatch #USA https://ift.tt/kfDTQAt

    Post summary

    Apple released patches for older iPhones and iPads to address kernel and WebKit CVEs that were actively exploited by the Coruna exploit kit, highlighting the need for users to apply the new fixes.

    00010214
    3.7K followersView on X
  • kawn@kawn2020
    Patch

    #AppleUpdate #iOS #iPadOS Apple が iOS 15.8.7 および iPadOS 15.8.7 リリース. CVE ベースで 4 件の脆弱性に対処. ・CVE-2023-41974 「This fix associated with the Coruna exploit was shipped in iOS 17 on September 18, 2023.」 https://x.com/kawn2020/status/2032047861765157288

    Post summary

    Apple released iOS 15.8.7 and iPadOS 15.8.7, addressing four CVEs including CVE‑2023‑41974, and shipped a patch for a previously known Coruna exploit in iOS 17.

    1000082
    89 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🚨 BREAKING: CISA adds FIVE new vulnerabilities to its Known Exploited Vulnerabilities Catalog! 🚨 🔍 CVE-2017-7921: Hikvision Improper Authentication 🔍 CVE-2021-22681: Rockwell Insufficient Protected Credentials 🔍 CVE-2021-30952: Apple Integer Overflow 🔍 CVE-2023-41974: Apple iOS/iPadOS Use-After-Free 🔍 CVE-2023-43000: Apple Use-After-Free ⚠️ These vulnerabilities are actively exploited and pose serious risks to federal systems. All organizations are urged to prioritize patching these vulnerabilities NOW to safeguard against cyber threats. Stay vigilant, stay protected! #NerdieNews #CyberSecurity #BreakingNews

    Post summary

    CISA has flagged five CVEs as actively exploited, and the post stresses immediate patching to protect federal systems.

    0000068
    49 followersView on X
  • Christina Ayiotis, Esq., CRM, CIPP/E, AIGP@christinayiotis
    Patch

    "patched .. underlying vulnerabilities in iOS updates .. over .. 2 years .. fixes for users who cannot update ..latest version. Specifically, iOS and iPadOS 15.8.7 patch 4 vulnerabilities: CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010" https://www.securityweek.com/apple-updates-older-ios-versions-to-patch-coruna-exploits/

    Post summary

    Apple released iOS 15.8.7 and iPadOS 15.8.7 updates that patch four CVEs (CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, CVE-2023-43010) for users who cannot upgrade to newer versions.

    00000133
    3.5K followersView on X
  • セキュリティ・トレンド bot だった@sec_trend
    Active Exploitation

    CISAがCoruna関連のiOS 脆弱性 3件をKEV追加 iOS 13〜17.2.1を狙う23件の攻撃キット対応 ... https://rocket-boys.co.jp/security-measures-lab/cisa-adds-ios-coruna-flaws-to-kev-cve-2023-41974-2021-30952-2023-43000/ #izumino_trend

    Post summary

    CISA has added three iOS Coruna-related vulnerabilities to the KEV list, citing active exploitation by 23 attack kits targeting iOS 13‑17.2.1.

    00000109
    2.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    CISAがCoruna関連のiOS 脆弱性 3件をKEV追加 iOS 13〜17.2.1を狙う23件の攻撃キット対応(CVE-2023-41974,CVE-2021-30952,CVE-2023-43000) https://rocket-boys.co.jp/security-measures-lab/cisa-adds-ios-coruna-flaws-to-kev-cve-2023-41974-2021-30952-2023-43000/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    CISA has added three Coruna-related iOS CVEs to its KEV list and noted that 23 attack kits target iOS 13–17.2.1, indicating that the vulnerabilities are already being exploited in the wild.

    00000104
    334 followersView on X
  • RagingCISO@CisoRaging77913
    Patch

    CVE-2021-30952, CVE-2023-41974, CVE-2023-43000: iOS exploits from 2021 still working in 2026. Coruna kit passed hands: US surveillance → state actors → Chinese criminals. Zero-day recycling market is real. Update your iPhones. Please.

    Post summary

    The post warns that iOS exploits from 2021 and newer CVEs are still active in 2026, underscores the persistence of the zero‑day recycling market, and urges users to update their iPhones.

    0000059
    5 followersView on X
  • xkzDB@xkzdb
    Patch

    🚨 CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit. <<<IMPORTANT>>> ⚡️ CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 added to CISA KEV catalog ⚡️ Coruna exploit kit uses 23 exploits across five chains targeting iOS 13–17.2.1 ⚡️ Deployed by threat actors for spyware, espionage, and stealing crypto wallets via PlasmaLoader ⚡️ Federal agencies must patch per BOD 22-01 Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA issued a patch directive for three iOS CVEs after confirming they were actively exploited in cyberespionage and crypto-theft campaigns using the Coruna exploit kit.

    0000096
    265 followersView on X
  • Fernando Karl@fernandokarl
    Disclosure

    🚨 Atenção usuários de Apple! A vulnerabilidade CVE-2023-41974 em iOS e iPadOS permite execução de código arbitrário com privilégios de kernel. Aplique as mitigações recomendadas ou descontinue o uso do produto. Mantenha sua segurança em dia! #CyberSecurity #InfoSec #CVE

    Post summary

    The tweet announces CVE-2023-41974, stating it allows arbitrary code execution with kernel privileges on iOS/iPadOS, and urges users to apply recommended mitigations or stop using the product.

    0000044
    255 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    General

    CVE-2021-30952 Apple 複数製品の整数オーバーフローまたはラップアラウンド脆弱性 CVE-2023-41974 Apple iOSおよびiPadOSのメモリ使用後の脆弱性 CVE-2023-43000 Apple 複数製品のメモリ解放後使用の脆弱性

    Post summary

    The snippet lists three Apple CVEs with brief vulnerability types but provides no evidence of exploitation, PoC, or patch information.

    0000058
    47 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、5つの既知の脆弱性をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 5) CVE-2017-7921 Hikvision 複数製品における不適切な認証の脆弱性 CVE-2021-22681 Rockwell 複数製品における保護された資格情報の不十分な脆弱性 CVE-2021-30952 Apple 複数製品の整数オーバーフローまたはラップアラウンド脆弱性 CVE-2023-41974 Apple iOSおよびiPadOSのメモリ使用後の脆弱性 CVE-2023-43000 Apple 複数製品のメモリ解放後使用の脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has announced five previously known and actively exploited vulnerabilities that have been added to its catalog, highlighting the need for immediate attention.

    00000256
    4.7K followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-41974 #Apple iOS and iPadOS Use-After-Free Vulnerability https://www.scyscan.com/cve-2023-41974/apple-ios-and-ipados-use-after-free-vulnerability/

    Post summary

    CVE-2023-41974 is an actively exploited use‑after‑free flaw in Apple iOS and iPadOS, noted in the latest CISA KEV list, with no patch or exploit code details provided in the short announcement.

    0000058
    57 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2023-41974 - Apple - iOS and iPadOS - https://www.redpacketsecurity.com/cve-alert-cve-2023-41974-apple-ios-and-ipados/ #OSINT #ThreatIntel #CyberSecurity #cve-2023-41974 #apple #ios-and-ipados

    Post summary

    The text announces CVE‑2023‑41974 for Apple iOS and iPadOS, providing a link for further reading but lacking exploitation details or mitigation information.

    00000130
    3.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more