A validation issue was addressed with improved logic. This issue is fixed in watchOS 9.6.2, iOS 16.6.1 and iPadOS 16.6.1. A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
No PoCs from references.
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/Ostorlab/KEV
- https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
- https://github.com/RENANZG/My-Debian-GNU-Linux
- https://github.com/RENANZG/My-Forensics
- https://github.com/houjingyi233/macOS-iOS-system-security
- https://github.com/rafsys/My-Forensics