Severity
High
Analysis Summary
CVE-2023-41990
Apple iOS and iPadOS could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of caches in the FontParser. By persuading a victim to open a specially crafted font file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
- Code Execution
Indicators Of Compromise
CVE
- CVE-2023-41990
Affected Vendors
Apple
Affected Products
- Apple iOS 16.2
- Apple iPadOS 16.2
Remediation
Refer to Apple security document for patch, upgrade or suggested workaround information.