Apple iOS and iPadOS Use-After-Free Vulnerability

Release Date: 05th of March 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2023-41974 is a high-severity memory corruption vulnerability (CVSS 7.8) affecting Apple mobile operating systems. The flaw is classified as a Use-After-Free (CWE-416) vulnerability in the system’s kernel memory management.

A use-after-free vulnerability occurs when a program continues to use a memory pointer after the memory has already been freed. This can lead to memory corruption, allowing attackers to manipulate system memory and potentially execute malicious code.

 

References