Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2023-38606
Apple Multiple Products
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L N U N H N 5.5 .0290 86.5 YES
AFFECTED
Product Versions Fixed
tvOS unspecified – —
iOS and iPadOS unspecified – —
macOS unspecified – —
iOS and iPadOS unspecified – —
macOS unspecified – —
macOS unspecified – —
watchOS unspecified – —
TIMELINE
Jul 20 Reserved by apple
Jul 26 Added to CISA KEV, remediation due 2023-08-16
Jul 26 Published (CNA: apple)
Description
This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 20, 2023 | Reserved | Reserved by apple |
| July 26, 2023 | KEV ADDED | Added to CISA KEV, remediation due 2023-08-16 |
| July 26, 2023 | Published | Published (CNA: apple) |
Affected
Affected products and packages — 7 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Apple | tvOS | — | unspecified | — |
| Apple | iOS and iPadOS | — | unspecified | — |
| Apple | macOS | — | unspecified | — |
| Apple | iOS and iPadOS | — | unspecified | — |
| Apple | macOS | — | unspecified | — |
| Apple | macOS | — | unspecified | — |
| Apple | watchOS | — | unspecified | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2023-38606 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.