CVE-2023-41061

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: Feb. 18, 2026 18 articles

EPSS Score

Source: FIRST.org · 2026-05-24
1.15%
probability
This CVE has a 1.15% probability of being exploited in the next 30 days.
0% Top 78.7th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
A validation issue in Wallet

Attack Intelligence

Google Project Zero

Patched
Sept. 7, 2023
Reported by
Apple
Root Cause Analysis
???
Security Advisory 2023-061
CERT-EU Sep 08, 2023

Signal Intelligence

Confidence
92%
EPSS 1.15%
Mentions 18
Last Seen Mar 11, 2025

CNA Information

Analyst Note

CVE-2023-41061 is confirmed as an actively exploited zero-day with strong supporting evidence: Apple's official acknowledgment of active exploitation, high CVSS score (7.8), reporting by Project Zero, and multiple credible sources documenting real-world attacks on iOS/iPadOS devices. The vulnerability involves arbitrary code execution through maliciously crafted attachments, representing a significant threat to affected Apple users.

Triage Info

Decided atFeb 18, 2026