CVE-2023-23494: Apple iPadOS

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 16.4 and iPadOS 16.4. A user in a privileged network position may be able to cause a denial-of-service.

Affected products

  • Apple iPadOS: before 16.4 (fixed in 16.4)
  • Apple iPhone OS: before 16.4 (fixed in 16.4)

Published 2023-05-08. Last modified 2026-06-17.