-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2023-07-24-3 iOS 15.7.8 and iPadOS 15.7.8 iOS 15.7.8 and iPadOS 15.7.8 addresses the following issues. Information about the security content is also available at https://support.apple.com/kb/HT213842. Apple maintains a Security Updates page at https://support.apple.com/HT201222 which lists recent software updates with security advisories. Apple Neural Engine Available for devices with Apple Neural Engine: iPhone 8 and later, iPad Pro (3rd generation) and later, iPad Air (3rd generation) and later, and iPad mini (5th generation) Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2023-23540: Mohamed GHANNAM (@_simo36) Find My Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: An app may be able to read sensitive location information Description: A logic issue was addressed with improved restrictions. CVE-2023-32416: Wojciech Regula of SecuRing (wojciechregula.blog) Kernel Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: An app may be able to execute arbitrary code with kernel privileges Description: The issue was addressed with improved memory handling. CVE-2023-32441: Peter Nguyễn Vũ Hoàng (@peternguyen14) of STAR Labs SG Pte. Ltd. Kernel Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1. Description: This issue was addressed with improved state management. CVE-2023-38606: Valentin Pashkov, Mikhail Vinogradov, Georgy Kucherin (@kucher1n), Leonid Bezvershenko (@bzvr_), and Boris Larin (@oct0xor) of Kaspersky Kernel Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: An app may be able to execute arbitrary code with kernel privileges Description: A use-after-free issue was addressed with improved memory management. CVE-2023-32433: Zweig of Kunlun Lab CVE-2023-35993: Kaitao Xie and Xiaolong Bai of Alibaba Group WebKit Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: A website may be able to bypass Same Origin Policy Description: The issue was addressed with improved checks. WebKit Bugzilla: 256549 CVE-2023-38572: Narendra Bhati (twitter.com/imnarendrabhati) of Suma Soft Pvt. Ltd, Pune - India WebKit Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: A remote attacker may be able to break out of Web Content sandbox. Apple is aware of a report that this issue may have been actively exploited. Description: The issue was addressed with improved bounds checks. WebKit Bugzilla: 255350 CVE-2023-32409: Clément Lecigne of Google's Threat Analysis Group and Donncha Ó Cearbhaill of Amnesty International’s Security Lab WebKit Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: Processing web content may lead to arbitrary code execution Description: The issue was addressed with improved checks. WebKit Bugzilla: 256865 CVE-2023-38594: Yuhao Hu WebKit Process Model Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: Processing web content may lead to arbitrary code execution Description: The issue was addressed with improved checks. WebKit Bugzilla: 258100 CVE-2023-38597: 이준성(Junsung Lee) of Cross Republic WebKit Web Inspector Available for: iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), and iPod touch (7th generation) Impact: Processing web content may disclose sensitive information Description: The issue was addressed with improved checks. WebKit Bugzilla: 256932 CVE-2023-38133: YeongHyeon Choi (@hyeon101010) Additional recognition Mail We would like to acknowledge Parvez Anwar for their assistance. WebRTC We would like to acknowledge an anonymous researcher for their assistance. This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from https://www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "iOS 15.7.8 and iPadOS 15.7.8". All information is also posted on the Apple Security Updates web site: https://support.apple.com/en-us/HT201222. This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEBP+4DupqR5Sgt1DB4RjMIDkeNxkFAmS/FLYACgkQ4RjMIDke Nxk6XA/+ORuxlrcXKaoFJwp+3yCiGxdQEcUKKzno529C0BVuN/19LgF9D3Bv+I4o xvtLCkxj8uOXOQR54Cp3Lhs4zWR174JXtU6k7YrkDig2VlSQU6TCi+duMLklR1W8 wm/M42vGH17GV4EpznbIPRW6HfnLqeYvjtbZV+znVjRfZRLUUh9FNlv72jPWkE4q wj+U4t7cobDWnkpVESmZM0tAOpAunJHwNuqebZjd4Et41F7WPalhxIAW9N9bIubc KgZAiHk9mZUt5TvBZyjzHxAilMrv+7MmvDQxjgdMKlwxz9/R+tvjqZJH6erAbJbI 8uZnPSBQX69Ytl23Fkt/t4cmeDQdKR1L74hE5+X+x2v7vVVm35Kup6jp9vJgpu3J F154ygXN5mJ8peKy0M8i/GjvQh5cF3yx3s5KrpghLX1TY3eH4U9lSM4/Ui6xJlJ2 u7F6d6ZLTBMucNNTIH1JDO+3iQlK0ySulS8F1FzD6lAtLWTFffWroXgj9vr9a1dS HimreNd/Q0CIHTycvdGpz7n2r2xR8krem7AV+LKkhx1TiVMKDuyCqlq60YtmXABr L2F63OXuN9WPiAHqB9IETwzSDCr2lsVJwkLMO5AKtFkiET/aRPrQ3YDtwJ9EY8BR meCx4jQRFoVwYNgkrooJ49crLSXF1IFPDv/LcUk8QV9nffIMvy0= =Mn3F -----END PGP SIGNATURE-----