CVE-2023-38603: Apple iPadOS

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A remote user may be able to cause a denial-of-service.

Affected products

  • Apple iPadOS: before 15.7.8 (fixed in 15.7.8); from 16.0, before 16.6 (fixed in 16.6)
  • Apple iPhone OS: before 15.7.8 (fixed in 15.7.8); from 16.0, before 16.6 (fixed in 16.6)
  • Apple macOS: before 11.7.9 (fixed in 11.7.9); from 12.0, before 12.6.8 (fixed in 12.6.8); from 13.0, before 13.5 (fixed in 13.5)

Published 2023-07-27. Last modified 2026-06-17.