CVE-2023-42916
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: Feb. 18, 2026
11 articles
EPSS Score
Source: FIRST.org · 2026-05-24
0.05%
probability
This CVE has a 0.05% probability
of being exploited in the next 30 days.
0%
Top 15.8th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroOut of bounds read
Attack Intelligence
Google Project Zero
Patched
Nov. 30, 2023
Reported by
Clément Lecigne of Google's Threat Analysis Group
Root Cause Analysis
???
Apple fixes zero-day exploited in 'extremely sophisticated' attacks
BleepingComputer
Feb 10, 2025
Apple fixes this year’s first actively exploited zero-day bug
BleepingComputer
Jan 27, 2025
Apple fixes two zero-days used in attacks on Intel-based Macs
BleepingComputer
Nov 19, 2024
Apple fixes two new iOS zero-days exploited in attacks on iPhones
BleepingComputer
Mar 05, 2024
Apple fixes first zero-day bug exploited in attacks this year
BleepingComputer
Jan 22, 2024
Apple emergency updates fix recent zero-days on older iPhones
BleepingComputer
Dec 11, 2023
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
BleepingComputer
Mar 11, 2025
Apple fixes two new iOS zero-days in emergency updates
BleepingComputer
Nov 30, 2023
Apple backports fix for zero-day exploited in attacks to older iPhones
BleepingComputer
May 13, 2024
Signal Intelligence
Confidence
92%
EPSS
0.05%
Mentions
11
Last Seen
Mar 11, 2025
CNA Information
Analyst Note
This CVE is confirmed as an actively exploited zero-day with strong evidence of real-world attacks described as 'extremely sophisticated' by Apple and documented by Google Project Zero. Multiple credible sources (BleepingComputer) corroborate active exploitation in the wild, and Apple has issued security patches across iOS, iPadOS, macOS, and Safari, with explicit acknowledgment of prior exploitation.
Triage Info
Decided atFeb 18, 2026