---
title: "Apple fixes 0-Day Vulnerability in Older Operating Systems"
canonical: "https://www.virtcloudrocks.com/space/INFOSEC/blog/852375/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems"
format: markdown
---
This update fixes the ImageIO vulnerability Apple patched for current operating systems last week. Now, Apple follows up with a patch for its older, but still supported, operating system versions. According to Citizen Lab, this vulnerability is already being exploited. Exploitation took advantage of the ImageIO vulnerability and a vulnerability in the Apple wallet "PassKit" API to send a "Pass" to the victim, including the malicious image. These older operating systems support PassKit, but it needs to be clarified if they are vulnerable to the PassKit issue. More details: Apple:  https://support.apple.com/en-us/HT201222 Citizen Lab:  https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/ Read the full entry: https://isc.sans.edu/diary/Apple+fixes+0Day+Vulnerability+in+Older+Operating+Systems/30210/ ============ CVE-2023-41064 - macOS Ventura, iOS, and iPadOS versions 13.5.2, 16.6.1 are susceptible to arbitrary code execution due to a buffer overflow issue involving image processing, potentially being actively exploited. Product: Apple macOS, iOS, and iPadOS CVSS Score: 7.8 ** KEV since 2023-09-11 ** NVD:  https://nvd.nist.gov/vuln/detail/CVE-2023-41064 ISC Diary:  https://isc.sans.edu/diary/30210 NVD References:  -  https://support.apple.com/en-us/HT213905 -  https://support.apple.com/en-us/HT213906 -  https://support.apple.com/en-us/HT213913 -  https://support.apple.com/en-us/HT213914 -  https://support.apple.com/en-us/HT213915 ============= CVE-2023-41061 - watchOS, iOS, and iPadOS versions 9.6.2, 16.6.1, and 16.6.1 allow for arbitrary code execution through a malicious attachment, with reports of active exploitation. Product: Apple watchOS, iOS, and iPadOS CVSS Score: 7.8 ** KEV since 2023-09-11 ** NVD:  https://nvd.nist.gov/vuln/detail/CVE-2023-41061 NVD References:  -  http://seclists.org/fulldisclosure/2023/Sep/4 -  http://seclists.org/fulldisclosure/2023/Sep/5 -  https://support.apple.com/en-us/HT213905 -  https://support.apple.com/en-us/HT213907 -  https://support.apple.com/kb/HT213905 -  https://support.apple.com/kb/HT213907 Apple Releases iOS/iPadOS 16.6.1, macOS 13.5.2, watchOS 9.6.2 fixing two zeroday vulnerabilities Published: 2023-09-07 Last Updated: 2023-09-08 14:57:04 UTC by Johannes Ullrich (Version: 1) Read the full entry: https://isc.sans.edu/diary/Apple+Releases+iOSiPadOS+1661+macOS+1352+watchOS+962+fixing+two+zeroday+vulnerabilities/30200/