CVE-2023-45866: Apple iPadOS

Medium severity, CVSS 6.3. EPSS: 7.9% chance of exploitation in the next 30 days.

Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.

Affected products

  • Apple iPadOS: before 17.2 (fixed in 17.2)
  • Apple iPhone OS: version 16.6 only; before 17.2 (fixed in 17.2)
  • Apple macOS: version 12.6.7 only; version 13.3.3 only; from 14.0, before 14.2 (fixed in 14.2)
  • Canonical Ubuntu Linux: version 18.04 only; version 20.04 only; version 22.04 only; version 23.10 only
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 38 only; version 39 only
  • Google Android: version 4.2.2 only; version 6.0.1 only; version 10.0 only; version 11.0 only; version 13.0 only; version 14.0 only

Published 2023-12-08. Last modified 2026-06-17.