CVE-2023-41064
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: Feb. 18, 2026
19 articles
EPSS Score
Source: FIRST.org · 2026-05-24
85.35%
probability
This CVE has a 85.35% probability
of being exploited in the next 30 days.
0%
Top 99.4th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroBuffer overflow in ImageIO
Attack Intelligence
Google Project Zero
Patched
Sept. 7, 2023
Reported by
The Citizen Lab at The University of Toronto's Munk School
Root Cause Analysis
???
Exploits & PoC
MrR0b0t19/CVE-2023-41064
PoC CVE-2023-41064 — MrR0b0t19/CVE-2023-41064
3
MrR0b0t19/vulnerabilidad-LibWebP-CVE-2023-41064
longitudes de código para desencadenar esta vulnerabilidad
0
2 repos — triés par ⭐
Rechercher sur GitHub ↗
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
BleepingComputer
Feb 10, 2025
Apple fixes this year’s first actively exploited zero-day bug
BleepingComputer
Jan 27, 2025
Apple fixes iOS Kernel zero-day vulnerability on older iPhones
BleepingComputer
Oct 12, 2023
Apple emergency update fixes new zero-day used to hack iPhones
BleepingComputer
Oct 04, 2023
Apple fixes two zero-days used in attacks on Intel-based Macs
BleepingComputer
Nov 19, 2024
Apple emergency updates fix 3 new zero-days exploited in attacks
BleepingComputer
Sep 21, 2023
Apple discloses 2 new zero-days exploited to attack iPhones, Macs
BleepingComputer
Sep 07, 2023
Apple fixes two new iOS zero-days exploited in attacks on iPhones
BleepingComputer
Mar 05, 2024
Apple fixes first zero-day bug exploited in attacks this year
BleepingComputer
Jan 22, 2024
Apple emergency updates fix recent zero-days on older iPhones
BleepingComputer
Dec 11, 2023
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
BleepingComputer
Mar 11, 2025
Apple fixes two new iOS zero-days in emergency updates
BleepingComputer
Nov 30, 2023
Apple backports BLASTPASS zero-day fix to older iPhones
BleepingComputer
Sep 12, 2023
Recently patched Apple, Chrome zero-days exploited in spyware attacks
BleepingComputer
Sep 22, 2023
Security Advisory 2023-061
CERT-EU
Sep 08, 2023
Google assigns new maximum rated CVE to libwebp bug exploited in attacks
BleepingComputer
Sep 26, 2023
Signal Intelligence
Confidence
95%
EPSS
85.35%
Mentions
19
Last Seen
Mar 11, 2025
CNA Information
Analyst Note
CVE-2023-41064 is confirmed as an actively exploited zero-day with strong evidence: Apple explicitly acknowledged active exploitation in their official advisory, the vulnerability is documented in Google Project Zero, and multiple credible sources report it was used in sophisticated attacks. The HIGH CVSS score (7.8) combined with real-world exploitation activity and official vendor confirmation provides very high confidence in this classification.
Triage Info
Decided atFeb 18, 2026