CVE-2023-27949: Apple iPadOS

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, iOS 15.7.4 and iPadOS 15.7.4. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

Affected products

  • Apple iPadOS: before 15.7.4 (fixed in 15.7.4)
  • Apple iPhone OS: before 15.7.4 (fixed in 15.7.4)
  • Apple macOS: from 12.0, before 12.6.4 (fixed in 12.6.4); from 13.0, before 13.3 (fixed in 13.3)

Published 2023-05-08. Last modified 2026-06-17.