CVE-2023-41993
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: Feb. 18, 2026
19 articles
EPSS Score
Source: FIRST.org · 2026-05-24
24.16%
probability
This CVE has a 24.16% probability
of being exploited in the next 30 days.
0%
Top 96.2th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroUnspecified memory corruption
Attack Intelligence
Google Project Zero
Discovered
Sept. 12, 2023
Patched
Sept. 21, 2023
Reported by
Bill Marczak of The Citizen Lab at The University of Toronto's Munk School and Maddie Stone of Google's Threat Analysis Group
Root Cause Analysis
???
Exploits & PoC
po6ix/POC-for-CVE-2023-41993
PoC CVE-2023-41993 — po6ix/POC-for-CVE-2023-41993
203
hrtowii/cve-2023-41993-test
testing poc
16
0x06060606/CVE-2023-41993
CVE-2023-41993
5
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
BleepingComputer
Feb 10, 2025
Apple fixes this year’s first actively exploited zero-day bug
BleepingComputer
Jan 27, 2025
Apple fixes iOS Kernel zero-day vulnerability on older iPhones
BleepingComputer
Oct 12, 2023
Apple emergency update fixes new zero-day used to hack iPhones
BleepingComputer
Oct 04, 2023
Apple fixes two zero-days used in attacks on Intel-based Macs
BleepingComputer
Nov 19, 2024
Apple emergency updates fix 3 new zero-days exploited in attacks
BleepingComputer
Sep 21, 2023
Apple fixes two new iOS zero-days exploited in attacks on iPhones
BleepingComputer
Mar 05, 2024
Apple fixes first zero-day bug exploited in attacks this year
BleepingComputer
Jan 22, 2024
Apple emergency updates fix recent zero-days on older iPhones
BleepingComputer
Dec 11, 2023
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
BleepingComputer
Mar 11, 2025
Apple fixes two new iOS zero-days in emergency updates
BleepingComputer
Nov 30, 2023
Recently patched Apple, Chrome zero-days exploited in spyware attacks
BleepingComputer
Sep 22, 2023
Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
BleepingComputer
Aug 29, 2024
Security Advisory 2023-069
CERT-EU
Oct 06, 2023
Signal Intelligence
Confidence
92%
EPSS
24.16%
Mentions
19
Last Seen
Mar 11, 2025
CNA Information
Analyst Note
CVE-2023-41993 is confirmed as an actively exploited zero-day affecting macOS and iOS with high CVSS score (8.8), documented in-the-wild exploitation by sophisticated threat actors, and Apple's official acknowledgment with patches deployed in macOS Sonoma 14. Multiple credible sources corroborate active exploitation against real systems prior to patch availability.
Threat Actors 9
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Infy
apt_group
Information theft and espionage
🇮🇷 IR
APT24
apt_group
Information theft and espionage
🇨🇳 CN
UNC1549
apt_group
Information theft and espionage
🇮🇷 IR
Pat Bear
apt_group
🇸🇾 SY
PassCV
apt_group
Information theft and espionage
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atFeb 18, 2026