CVE-2023-23528: Apple iPadOS
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 16.4, iOS 16.4 and iPadOS 16.4. Processing a maliciously crafted Bluetooth packet may result in disclosure of process memory.
Affected products
- Apple iPadOS: before 16.4 (fixed in 16.4)
- Apple iPhone OS: before 16.4 (fixed in 16.4)
- Apple tvOS: before 16.4 (fixed in 16.4)
Published 2023-05-08. Last modified 2026-06-17.