CVE-2023-38606

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: Feb. 18, 2026 20 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.11%
probability
This CVE has a 0.11% probability of being exploited in the next 30 days.
0% Top 29.6th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Unspecified kernel vulnerability against pre-iOS 15.7.1

Google Project Zero

Patched
July 24, 2023
Reported by
Valentin Pashkov, Mikhail Vinogradov, Georgy Kucherin (@kucher1n), Leonid Bezvershenko (@bzvr_), and Boris Larin (@oct0xor) of Kaspersky
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 0.11%
Mentions 20
Last Seen Mar 12, 2026

CNA Information

Analyst Note

This CVE is confirmed as an actively exploited zero-day with evidence of sophisticated real-world attacks documented by Google Project Zero and multiple security publications. The vulnerability affects kernel state management across multiple Apple platforms and was patched across iOS, macOS, tvOS, and watchOS versions, indicating broad impact and validation of the threat.

Threat Actors 1

Kimsuky
apt_group Information theft and espionage 🇰🇷 KR

Triage Info

Decided atFeb 18, 2026