CVE-2023-41993PoC(apple / active_iq_unified_manager)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple active_iq_unified_manager systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-10-16. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-754

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • cloud_insights_acquisition_unit
  • cloud_insights_storage_workload_security_agent
  • debian_linux

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-13); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Products
active_iq_unified_managercloud_insights_acquisition_unitcloud_insights_storage_workload_security_agentdebian_linuxfedoragraalvmipadosiphone_osjdkjre

9 versions affected across 14 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-13: 3Mentions · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-13: 3Exploit Tool / Code · 2026-03-13: 3Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-13: 103-1303-15
Signal classification2 categories
PoC
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-133
PoC3
2026-03-151
General1
Full discourse4 posts
  • Silzee@SilzeeJailbreak
    PoC

    CVE-2023-41993 PoC exploit for CVE-2023-41993. It's written only up to addrof/fakeobj. Reliability is not great. If you want to make it better, try to spray structure IDs. https://github.com/po6ix/POC-for-CVE-2023-41993

    Post summary

    The post announces a proof‑of‑concept exploit for CVE‑2023‑41993, linking to a GitHub repository where the partial code is available.

    01045194.6K
    31.9K followersView on X
  • Hermes Tool@Hermes_tooll
    PoC

    CVSS score: 9.8 PoC: https://github.com/po6ix/POC-for-CVE-2023-41993 Patched version(s): Safari 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14 https://nvd.nist.gov/vuln/detail/CVE-2023-41993 #DarkWeb

    Post summary

    The post announces CVE‑2023‑41993 with a 9.8 CVSS score, shares a GitHub PoC, and lists the platform versions that have been patched.

    02023152.8K
    2.5K followersView on X
  • Hermes Tool@Hermes_tooll
    PoC

    CVE-2023-41993 PoC exploit for CVE-2023-41993. It's written only up to addrof/fakeobj. Reliability is not great. https://github.com/po6ix/POC-for-CVE-2023-41993

    Post summary

    A proof‑of‑concept exploit for CVE‑2023‑41993 has been posted on GitHub; it only covers addrof/fakeobj stages and is noted to be unreliable.

    020851.0K
    2.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2023-41993 3 - CVE-2025-64755 4 - CVE-2025-43300 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple list of the top five trending CVEs with no additional exploitation, patch, or technical detail information.

    00031347
    1.7K followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--
OSfedoraprojectfedora37--
OSfedoraprojectfedora38--
OSfedoraprojectfedora39--
Appnetappactive_iq_unified_manager-vsphere-
Appnetappactive_iq_unified_manager-windows-
Appnetappcloud_insights_acquisition_unit---
Appnetappcloud_insights_storage_workload_security_agent---
Appnetapponcommand_insight---
Appnetapponcommand_workflow_automation---
Apporaclegraalvm20.3.13--
Apporaclegraalvm21.3.9--
Apporaclejdk1.8.0--
Apporaclejre1.8.0--
Appwebkitgtkwebkitgtk\+---

Explore more