Apple has taken swift action by releasing an urgent security patch to address a critical vulnerability, identified as CVE-2023-42824. While Apple has remained characteristically tight-lipped about the specific details of the vulnerability, it has acknowledged that it impacts a range of its devices, including the iPhone XS and newer models, iPad Pro 12.9-inch 2nd generation and newer, iPad Pro 10.5-inch, iPad Pro 11-inch 1st generation and newer, iPad Air 3rd generation and newer, iPad 6th generation and newer, and iPad mini 5th generation and newer.
This vulnerability is classified as a local privilege escalation flaw within the kernel and, notably, it may have already been actively exploited in versions of iOS prior to iOS 16.6.
Furthermore, the emergency patch also addresses another vulnerability, labeled CVE-2023-5217, which pertains to a bug within the libvpx video codec library developed by Google and the Alliance for Open Media. This flaw involves a heap buffer overflow and was initially reported by Clément Lecigne from Google’s Threat Analysis Group.
Mozilla has also highlighted this issue, noting that it could result in remote code execution due to the specific handling of a maliciously controlled VP8 media stream. Notably, Mozilla has reported instances of this vulnerability being exploited in various other products.
To rectify this, Apple’s advisory recommends updating to libvpx version 1.13.1 to mitigate the CVE-2023-5217 vulnerability.


