CVE-2023-23526: Apple iPadOS

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A file from an iCloud shared-by-me folder may be able to bypass Gatekeeper.

Affected products

  • Apple iPadOS: before 16.4 (fixed in 16.4)
  • Apple iPhone OS: before 16.4 (fixed in 16.4)
  • Apple macOS: before 13.3 (fixed in 13.3)

Published 2023-05-08. Last modified 2026-06-17.