CVE-2023-28208: Apple iPadOS

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.2, iOS 16.3 and iPadOS 16.3. A user may send a text from a secondary eSIM despite configuring a contact to use a primary eSIM.

Affected products

  • Apple iPadOS: before 16.3 (fixed in 16.3)
  • Apple iPhone OS: before 16.3 (fixed in 16.3)
  • Apple macOS: from 13.0, before 13.2 (fixed in 13.2)

Published 2023-09-06. Last modified 2026-06-17.