HomeSecurityCISA: New Apple vulnerabilities in the KEV List

CISA: New Apple vulnerabilities in the KEV Catalog

CISA has added three vulnerabilities affecting Apple devices and operating systems to its List of Known Exploitable Vulnerabilities (KEV) . According to the announcement, these vulnerabilities have already begun to be actively exploited by attackers, making it immediately security updates critical for organizations and users to install .

Apple CISA

On March 5, 2026, the agency added the three vulnerabilities to the KEV list, a list that tracks vulnerabilities that are actively used in cyberattacks. The inclusion of a vulnerability on this list is a strong indication that attackers have already developed exploitation tools or techniques, significantly increasing the risk of systems being compromised.

See also: Critical vulnerability in Nginx UI exposes backups

Apple: The three dangerous security flaws

The vulnerabilities, which were added, concern technical problems in memory management and arithmetic logic issues. Two of the most serious bugs are CVE-2023-43000 and CVE-2023-41974, which belong to the Use-After-Free. This is a known security issue that occurs when a program continues to use a memory pointer after it has already been freed or reallocated.

In such cases, an attacker can exploit incorrect memory management to inject malicious code into the program's operation. If the exploit is successful, the attacker can gain access to critical data or gain control of the system.

The third vulnerability, CVE-2021-30952, is an Integer Overflow vulnerability. This vulnerability occurs when a numerical operation produces a value larger than can be stored in the available memory space. The result is unpredictable software behavior, which can be exploited to execute arbitrary code.

See also: OAuth vulnerability in n8n platform leads to system breach

CISA: New Apple vulnerabilities in the KEV Catalog

Which platforms are affected?

The vulnerabilities affect multiple Apple products and operating systems:

  • CVE-2023-43000 affects macOS, iOS, iPadOS, and Safari 16.6, potentially causing memory corruption.
  • CVE-2021-30952 affects tvOS, macOS, Safari, iPadOS, and watchOS, leading to arbitrary code execution.
  • CVE-2023-41974 severely affects iOS and iPadOS, allowing a malicious application to execute arbitrary code with kernel privileges to access the system.

Attacks that exploit these vulnerabilities can even be triggered through malicious content on the internet, if the user is tricked into interacting with it. A specially crafted file or a malicious website can be the starting point for an attack.

The threat to organizations and businesses

While it is not yet confirmed whether these vulnerabilities are being used in organized ransomware campaigns, CISA notes that the potential for arbitrary code execution and kernel-level access pose particularly serious risks. In corporate environments, such a breach could lead to complete control of systems, data theft , or the installation of additional malware.

See also: WordPress: Vulnerability in the User Registration & Membership plugin

The rise in attacks targeting corporate devices and cloud infrastructure has made rapid deployment of security updates a key component of a cybersecurity strategy. Many organizations are now implementing continuous monitoring and automated patch management to reduce the time of exposure to such risks.

CISA: New Apple vulnerabilities in the KEV Catalog

CISA deadline and guidelines

Under Binding Operational Directive BOD 22-01, US federal agencies are required to protect their networks from these threats by March 26, 2026.Although the directive primarily concerns government organizations, CISA strongly recommends that the private sector take immediate action.

System administrators are urged to install all available Apple security updates, follow cloud-based guidelines , and temporarily discontinue use of vulnerable products if a fix is ​​not immediately available. Rapid response is considered critical to preventing attacks that could compromise critical data and infrastructure.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS