CVE-2023-41061: Apple iOS, iPadOS, and watchOS Wallet Code Execution Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2023-09-11. EPSS: 4.4% chance of exploitation in the next 30 days.

A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

Affected products

  • Apple iPadOS: before 16.6.1 (fixed in 16.6.1)
  • Apple iPhone OS: before 16.6.1 (fixed in 16.6.1)
  • Apple watchOS: before 9.6.2 (fixed in 9.6.2)

Published 2023-09-07. Last modified 2026-06-17.