CVE-2023-43000Active Exploitation(apple / ipados)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Active exploitation appears in 15 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 11 observed days

What's happening

  • Active exploitation reported across 15 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 8 signals
  • General: 3 classified signals
  • Peaked 9d ago at 5 mentions (2026-03-06); latest day: 1
  • 19 total mentions across 11 days

Affected systems

Vendors
Products
ipadosiphone_osmacossafari

Deep dive

Activity timeline19 mentions / 11d
01345Mentions · 2026-03-05: 2Mentions · 2026-03-06: 5Mentions · 2026-03-07: 4Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-04-11: 1PoC Mentioned / Linked · 2026-03-07: 1Exploit Tool / Code · 2026-03-06: 1Active Exploitation · 2026-03-05: 2Active Exploitation · 2026-03-06: 4Active Exploitation · 2026-03-07: 3Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-16: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-04-11: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-04-11: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-04-11: 103-0503-0603-0703-0903-1003-1103-1203-1403-1603-1704-11
Signal classification4 categories
Active Exploitation
1263.2%
General
315.8%
Patch
315.8%
Disclosure
15.3%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-03-052
Active Exploitation2
2026-03-065
Active Exploitation3General1Patch1
2026-03-074
Active Exploitation2Disclosure1General1
2026-03-091
General1
2026-03-101
Active Exploitation1
2026-03-111
Active Exploitation1
2026-03-121
Patch1
2026-03-141
Patch1
2026-03-161
Active Exploitation1
2026-03-171
Active Exploitation1
2026-04-111
Active Exploitation1
Full discourse19 posts
  • EdgeDetectOps@EdgeDetectOps
    Active Exploitation

    CVE-2023-43000: 2 billion Apple devices exposed through Safari. One poisoned link = full access to your data. This isn't theoretical — it's being exploited right now. 🚨 https://t.co/kOPFjwtRUQ

    Post summary

    The tweet asserts that CVE-2023-43000 is currently being exploited in the wild via a poisoned Safari link, but provides no technical details, PoC, or patches.

    1403092
    14 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに5件の脆弱性を追加。ハイクビジョンのCVE-2017-7921、Rockwell Automation製品のCVE-2021-22681、Apple製品のCVE-2021-30952、CVE-2023-41974、CVE-2023-43000。 https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA announced the inclusion of five CVEs in its catalog of known exploited vulnerabilities, confirming that these weaknesses are being actively exploited in the wild.

    10021821
    7.3K followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    🚨 BREAKING: CVE-2023-43000 hits Apple's entire ecosystem - macOS, iOS, iPadOS & Safari 16.6. Use-after-free vulnerability allows memory corruption through malicious web content. Added to KEV catalog with mandatory patching deadline.

    Post summary

    Apple’s entire ecosystem is affected by CVE-2023-43000, a use‑after‑free flaw that can corrupt memory through malicious web content; the vulnerability is listed in the KEV catalog with a mandatory patch deadline.

    1101092
    14 followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/5追加) 🛡️No.1533 CVE-2017-7921 Hikvision Multiple Products Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上で特権昇格を行う恐れがあります。また脆弱性の悪用により、機密情報にアクセスされる可能性があります。 https://www.hikvision.com/us-en/support/document-center/special-notices/privilege-escalating-vulnerability-in-certain-hikvision-ip-cameras/ 🛡️No.1534 CVE-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:認証情報の不十分な保護 (CWE-522 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、Studio 5000 Logix Designerソフトウェアにおいて、キーが発見される恐れがあります。このキーは、LogixコントローラがRockwell Automationの設計ソフトウェアと通信していることを確認するために使用されます。この脆弱性が悪用されると、不正なアプリケーションがLogixコントローラに接続できるようになる可能性があります。この脆弱性を悪用するには、不正なユーザーがコントローラへのネットワークアクセスが必要になります。 https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 🛡️No.1535 CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:整数オーバーフローまたはラップアラウンド (CWE-190 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT212975 https://support.apple.com/en-us/HT212976 https://support.apple.com/en-us/HT212978 https://support.apple.com/en-us/HT212980 https://support.apple.com/en-us/HT212982 🛡️No.1536 CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: アプリを介して、カーネル権限で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT213938 https://support.apple.com/kb/HT213938 🛡️No.1537 CVE-2023-43000 Apple Multiple products Use-After-Free Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、メモリ破損が発生する恐れがあります。 https://support.apple.com/en-us/120324 https://support.apple.com/en-us/120331 https://support.apple.com/en-us/120338 CISA Adds Five Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has confirmed exploitation of five CVEs, all of which have vendor‑issued patches or mitigations listed, indicating active exploitation in the wild.

    010203.5K
    42.6K followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Active Exploitation

    CVE-2023-43000: 2 billion Apple devices exposed through Safari. One poisoned link = full access to your data. This isn't theoretical — it's being exploited right now. 🚨 https://t.co/k9DXXn3krg

    Post summary

    The tweet claims that CVE‑2023‑43000 is actively exploited via poisoned Safari links, exposing data on billions of Apple devices, but provides no technical details or evidence beyond the assertion of in‑the‑wild attacks.

    1001090
    14 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨Cisco Catalyst SD-WANの脆弱性、さらに2件の悪用が明らかに:CVE-2026-20128、CVE-2026-20122 ⚠️米CISA、Apple製品の古い脆弱性3件をKEVカタログに追加(CVE-2023-43000、CVE-2021-30952、CVE-2023-41974) 〜サイバーアラート3月6日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44386/

    Post summary

    The post highlights recent Cisco SD‑WAN vulnerabilities with confirmed exploitation and a CISA KEV addition for Apple products, but offers no technical specifics, patches, or PoC references.

    01010195
    1.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2023-43000 Exploit in the wild confirmed for CVE-2023-43000 (CVSS 8.8). A use-after-free issue was addressed with improved memory management. This issue is fixed... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post alerts that CVE‑2023‑43000 is being actively exploited in the wild, notes a use‑after‑free flaw, and states a fix has been applied, but it provides no PoC or exploit code.

    0001099
    5.6K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/03/05:Apple macOS/iOS などにおける複数の脆弱性を登録 https://iototsecnews.jp/2026/03/09/cisa-warns-of-macos-and-ios-vulnerabilities-exploited-in-attacks/ Apple の製品群で発見された深刻な脆弱性は、主にメモリ管理と計算処理の不備に起因するものです。具体的には、CVE-2023-43000/CVE-2023-41974 におけるメモリ解放後使用の問題と、CVE-2021-30952 における整数オーバーフローの問題です。メモリ解放後使用とは、プログラムが再割り当て済みのメモリを参照し続けることで不正なコード実行を許すものであり、整数オーバーフローは、数値計算の結果が記憶領域の上限を超えてしまうものです。これらの脆弱性を悪用する攻撃者は、悪意の Web コンテンツを介して、カーネル権限でのコード実行などを引きこす恐れがあります。確実な更新適用で保護できますので、早めの対応が推奨されます。 #Apple #CISA #CVE202130952 #CVE202341974 #CVE202343000 #Exploit #Government #iOS #KEV #macOS #Vulnerability

    Post summary

    CISA warns that Apple macOS/iOS vulnerabilities (CVE‑2023‑43000, CVE‑2023‑41974, CVE‑2021‑30952) are being exploited in the wild; the post outlines the technical details and recommends applying updates promptly.

    01000143
    484 followersView on X
  • kawn@kawn2020
    Patch

    #AppleUpdate #iOS #iPadOS iOS 15.8.7 および iPadOS 15.8.7 ・CVE-2023-43000 「This fix associated with the Coruna exploit was shipped in iOS 16.6 on July 24, 2023.」 ・CVE-2023-43010 「This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023.」

    Post summary

    Both CVE‑2023‑43000 and CVE‑2023‑43010 were addressed by Apple with patches shipped in iOS 16.6 and iOS 17.2; the post contains no PoC, exploit details, signs of active exploitation, or false‑positive claims.

    1000060
    89 followersView on X
  • Grok@grok
    Active Exploitation

    Several Feb-Mar 2026 KEV additions include browser exploits: CVE-2026-2441 (Chromium CSS use-after-free, added Feb 17; hits Chrome/Edge/Opera via crafted HTML, active wild exploitation soon after). Also Apple Safari/web-content ones like CVE-2021-30952 (integer overflow) & CVE-2023-43000 (UAF), added Mar 5. No major defender surprises flagged beyond typical browser risks, but these prioritize patching. Check CISA catalog for full list (e.g., Mar 9 Ivanti/SolarWinds too).

    Post summary

    Several KEV CVEs, notably CVE-2026-2441, are actively exploited in the wild, and users are urged to patch affected browsers promptly.

    0100044
    8.4M followersView on X
  • EdgeDetectOps@EdgeDetectOps
    General

    Stay ahead of critical vulnerabilities like CVE-2023-43000. Follow @EdgeDetectOps for real-time threat intelligence. Get your FREE security audit: http://edgedetectops.com/audit #CyberSecurity #Apple #CVE #ThreatIntel #InfoSec

    Post summary

    The tweet references CVE-2023-43000 without detailing the vulnerability or providing any exploit information, and instead promotes a free security audit.

    0001084
    14 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    🚨 BREAKING: CISA adds FIVE new vulnerabilities to its Known Exploited Vulnerabilities Catalog! 🚨 🔍 CVE-2017-7921: Hikvision Improper Authentication 🔍 CVE-2021-22681: Rockwell Insufficient Protected Credentials 🔍 CVE-2021-30952: Apple Integer Overflow 🔍 CVE-2023-41974: Apple iOS/iPadOS Use-After-Free 🔍 CVE-2023-43000: Apple Use-After-Free ⚠️ These vulnerabilities are actively exploited and pose serious risks to federal systems. All organizations are urged to prioritize patching these vulnerabilities NOW to safeguard against cyber threats. Stay vigilant, stay protected! #NerdieNews #CyberSecurity #BreakingNews

    Post summary

    CISA announced that five listed CVEs are actively exploited in the wild and urgently recommends immediate patching.

    0000068
    49 followersView on X
  • Christina Ayiotis, Esq., CRM, CIPP/E, AIGP@christinayiotis
    Patch

    "patched .. underlying vulnerabilities in iOS updates .. over .. 2 years .. fixes for users who cannot update ..latest version. Specifically, iOS and iPadOS 15.8.7 patch 4 vulnerabilities: CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010" https://www.securityweek.com/apple-updates-older-ios-versions-to-patch-coruna-exploits/

    Post summary

    Apple has issued patches for older iOS/iPadOS versions, addressing four CVEs—including CVE-2023-41974—without any indication of active exploitation or PoC availability.

    00000133
    3.5K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    CISAがCoruna関連のiOS 脆弱性 3件をKEV追加 iOS 13〜17.2.1を狙う23件の攻撃キット対応(CVE-2023-41974,CVE-2021-30952,CVE-2023-43000) https://rocket-boys.co.jp/security-measures-lab/cisa-adds-ios-coruna-flaws-to-kev-cve-2023-41974-2021-30952-2023-43000/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    CISA has added three Coruna-related iOS CVEs to its KEV list, indicating confirmed in-the-wild exploitation, though the post does not provide PoC, exploit code, patches, or technical details.

    00000104
    334 followersView on X
  • RagingCISO@CisoRaging77913
    General

    CVE-2021-30952, CVE-2023-41974, CVE-2023-43000: iOS exploits from 2021 still working in 2026. Coruna kit passed hands: US surveillance → state actors → Chinese criminals. Zero-day recycling market is real. Update your iPhones. Please.

    Post summary

    The post alerts that certain iOS CVEs from 2021 remain exploitable in 2026 and urges users to update their devices, but it provides no technical or exploitation details.

    0000059
    5 followersView on X
  • xkzDB@xkzdb
    Patch

    🚨 CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit. <<<IMPORTANT>>> ⚡️ CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 added to CISA KEV catalog ⚡️ Coruna exploit kit uses 23 exploits across five chains targeting iOS 13–17.2.1 ⚡️ Deployed by threat actors for spyware, espionage, and stealing crypto wallets via PlasmaLoader ⚡️ Federal agencies must patch per BOD 22-01 Follow, repost, like, and comment on every post to help me spread awareness :)

    Post summary

    CISA has ordered federal agencies to patch three iOS CVEs (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000) that are actively exploited by the Coruna exploit kit for espionage and crypto‑theft operations.

    0000096
    265 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    General

    CVE-2021-30952 Apple 複数製品の整数オーバーフローまたはラップアラウンド脆弱性 CVE-2023-41974 Apple iOSおよびiPadOSのメモリ使用後の脆弱性 CVE-2023-43000 Apple 複数製品のメモリ解放後使用の脆弱性

    Post summary

    The text lists three Apple CVEs with brief type descriptors but offers no detailed technical info, PoC, patches, or evidence of active exploitation.

    0000058
    47 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、5つの既知の脆弱性をカタログに追加 CISA Adds Five Known Exploited Vulnerabilities to Catalog #CISA (Mar 5) CVE-2017-7921 Hikvision 複数製品における不適切な認証の脆弱性 CVE-2021-22681 Rockwell 複数製品における保護された資格情報の不十分な脆弱性 CVE-2021-30952 Apple 複数製品の整数オーバーフローまたはラップアラウンド脆弱性 CVE-2023-41974 Apple iOSおよびiPadOSのメモリ使用後の脆弱性 CVE-2023-43000 Apple 複数製品のメモリ解放後使用の脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog

    Post summary

    CISA added five CVEs—CVE-2017-7921, CVE-2021-22681, CVE-2021-30952, CVE-2023-41974, and CVE-2023-43000—to its catalog of known exploited vulnerabilities, confirming their abuse in the wild.

    00000256
    4.7K followersView on X
  • ScyScan@ScyScan
    Active Exploitation

    Latest Known Exploited Vulnerabilities (#KEV) : #CVE-2023-43000 #Apple Multiple products Use-After-Free Vulnerability https://www.scyscan.com/cve-2023-43000/apple-multiple-products-use-after-free-vulnerability/

    Post summary

    CVE‑2023‑43000, a use‑after‑free flaw in multiple Apple products, is currently being exploited in the wild, as indicated by its inclusion in a known‑exploited‑vulnerabilities list.

    0000053
    57 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---

Explore more