Toggle menu
Toggle preferences menu
Toggle personal menu
Not logged in
Log in or create an account to edit The Apple Wiki.
kfd (Smith)
Vulnerability in XNU
SoftwareiOS and macOS
Vulnerable in? - iOS 16.5, ? - macOS 13.4
Fixed iniOS 16.5.1, macOS 13.4.1
Disclosed1 May 2023 (2023-05-01)
Discovered byFélix Poulin-Bélanger, Kaspersky
CVECVE-2023-32434
Apple KBHT103837

CVE-2023-32434, also known as Smith, is an integer overflow in the XNU kernel that leads to a Physical Use After Free vulnerability. This was a bug collision, as it was also found to be being used as the kernel exploit in the Operation Triangulation chain. The exploit is available to use in Dopamine. Furthermore, it is reachable from the WebContent sandbox, which allowed it to be used in an in-the-wild malware chain.