CVE-2023-23520: Apple iPadOS

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

A race condition was addressed with additional validation. This issue is fixed in watchOS 9.3, tvOS 16.3, macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may be able to read arbitrary files as root.

Affected products

  • Apple iPadOS: before 16.3 (fixed in 16.3)
  • Apple iPhone OS: before 16.3 (fixed in 16.3)
  • Apple macOS: before 13.2 (fixed in 13.2)

Published 2023-02-27. Last modified 2026-06-17.