CVE-2023-42916

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: Feb. 18, 2026 11 articles

EPSS Score

Source: FIRST.org · 2026-05-24
0.05%
probability
This CVE has a 0.05% probability of being exploited in the next 30 days.
0% Top 15.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Out of bounds read

Attack Intelligence

Google Project Zero

Patched
Nov. 30, 2023
Reported by
Clément Lecigne of Google's Threat Analysis Group
Root Cause Analysis
???

Signal Intelligence

Confidence
92%
EPSS 0.05%
Mentions 11
Last Seen Mar 11, 2025

CNA Information

Analyst Note

This CVE is confirmed as an actively exploited zero-day with strong evidence of real-world attacks described as 'extremely sophisticated' by Apple and documented by Google Project Zero. Multiple credible sources (BleepingComputer) corroborate active exploitation in the wild, and Apple has issued security patches across iOS, iPadOS, macOS, and Safari, with explicit acknowledgment of prior exploitation.

Triage Info

Decided atFeb 18, 2026