CVE-2023-41990

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 3 articles

EPSS Score

Source: FIRST.org · 2026-05-24
2.69%
probability
This CVE has a 2.69% probability of being exploited in the next 30 days.
0% Top 86.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
TrueType font remote code execution in iOS 15.7

Google Project Zero

Patched
July 24, 2023
Reported by
Apple, Valentin Pashkov, Mikhail Vinogradov, Georgy Kucherin (@kucher1n), Leonid Bezvershenko (@bzvr_), and Boris Larin (@oct0xor) of Kaspersky
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 2.69%
Mentions 3
Last Seen Jan 01, 2024

CNA Information

Analyst Note

CVE-2023-41990 is a confirmed zero-day in Apple's font handling with active exploitation reported against iOS versions prior to 16.3, as acknowledged by Apple itself. The vulnerability carries a HIGH CVSS score (7.8), achieved arbitrary code execution capability, and was documented by Google Project Zero, providing strong technical validation.

Threat Actors 1

Kimsuky
apt_group Information theft and espionage 🇰🇷 KR

Triage Info

Decided atMar 03, 2026