CVE-2023-28208: Apple iPadOS
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may send a text from a secondary eSIM despite configuring a contact to use a primary eSIM.
Affected products
- Apple iPadOS: before 16.3 (fixed in 16.3)
- Apple iPhone OS: before 16.3 (fixed in 16.3)
- Apple macOS: from 13.0, before 13.2 (fixed in 13.2)
Published 2023-09-06. Last modified 2026-06-17.