CVE-2023-23529
Exploited before a patch existed (Apple: “may have been exploited”).
Export this CVE's branch rows: CSV · JSON · Permalink: /cve/CVE-2023-23529
- First fix
- (iOS 16.3.1 and iPadOS 16.3.1, macOS Ventura 13.2.1)
- CISA KEV added
- (1 day after the first fix)
- NVD published
- (14 days after the first fix)
First fix: The release date of the earliest Apple update (including Rapid Security Responses and Background Security Improvements) whose advisory lists the CVE.
KEV date added (proxy): CISA KEV “date added” is when CISA catalogued evidence of exploitation. It is a lagging proxy: exploitation started on or before that date, usually well before.
Fix per branch
Backport gap: For one CVE and one branch: the branch's first fix date minus the earliest fix date across all branches of the same platform.
No fix listed: The branch is still maintained (it shipped a security update after the earliest fix, or its last security update is under 180 days old), but no Apple advisory lists this CVE for it as of the data date. The branch may be unaffected; Apple does not publish “not affected” statements.
Branch ended: The branch shipped no security update after the earliest fix and none in the 180 days before the data date, so it is treated as ended and not counted as missing a backport. Updates without published CVE entries do not keep a branch alive.
Fixed at branch release: The branch was first released after the earliest fix, so it is not a backport and is not counted. “Listed”: its advisory names the CVE. “Inherited”: it does not, and the fix is assumed to be in the branch from its first release.
| Branch | Status | First fix on branch | Gap |
|---|---|---|---|
| iOS 27 | fixed at branch release (inherited) | first iOS 27 release | – |
| iOS 26 | fixed at branch release (inherited) | first iOS 26 release | – |
| iOS 18 | fixed at branch release (inherited) | first iOS 18 release | – |
| iOS 17 | fixed at branch release (inherited) | first iOS 17 release | – |
| iOS 16 | fixed with the earliest fix | iOS 16.3.1 and iPadOS 16.3.1 | 0 d |
| iOS 15 | fixed 42 days later | iOS 15.7.4 and iPadOS 15.7.4 | 42 d |
| iOS 14 | branch ended | – | – |
| iOS 13 | branch ended | – | – |
| iOS 12 | branch ended | – | – |
| Branch | Status | First fix on branch | Gap |
|---|---|---|---|
| iPadOS 27 | fixed at branch release (inherited) | first iPadOS 27 release | – |
| iPadOS 26 | fixed at branch release (inherited) | first iPadOS 26 release | – |
| iPadOS 18 | fixed at branch release (inherited) | first iPadOS 18 release | – |
| iPadOS 17 | fixed at branch release (inherited) | first iPadOS 17 release | – |
| iPadOS 16 | fixed with the earliest fix | iOS 16.3.1 and iPadOS 16.3.1 | 0 d |
| iPadOS 15 | fixed 42 days later | iOS 15.7.4 and iPadOS 15.7.4 | 42 d |
| iPadOS 14 | branch ended | – | – |
| iPadOS 13 | branch ended | – | – |
| Branch | Status | First fix on branch | Gap |
|---|---|---|---|
| macOS 27 Golden Gate | fixed at branch release (inherited) | first macOS 27 Golden Gate release | – |
| macOS 26 Tahoe | fixed at branch release (inherited) | first macOS 26 Tahoe release | – |
| macOS 15 Sequoia | fixed at branch release (inherited) | first macOS 15 Sequoia release | – |
| macOS 14 Sonoma | fixed at branch release (inherited) | first macOS 14 Sonoma release | – |
| macOS 13 Ventura | fixed with the earliest fix | macOS Ventura 13.2.1 | 0 d |
| macOS 12 Monterey | no fix listed | – | – |
| macOS 11 Big Sur | no fix listed | – | – |
| macOS 10 Catalina | branch ended | – | – |
Every Apple listing
Each release whose advisory lists CVE-2023-23529, with Apple's own notes.
| Release | Branch | Released | Entry added | Exploited note |
|---|---|---|---|---|
| iOS 16.3.1 and iPadOS 16.3.1 | iOS 16 | with release | yes | |
| iOS 16.3.1 and iPadOS 16.3.1 | iPadOS 16 | with release | yes | |
| macOS Ventura 13.2.1 | macOS 13 Ventura | with release | yes | |
| iOS 15.7.4 and iPadOS 15.7.4 | iOS 15 | with release | yes | |
| iOS 15.7.4 and iPadOS 15.7.4 | iPadOS 15 | with release | yes |