{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-28206",
  "revision": 1,
  "title": "Apple — the graphics surface component reaches the kernel",
  "summary": "An out-of-bounds write in the graphics surface component lets an app execute code with kernel privileges on an Apple device. It was fixed together with the browser flaw it was chained to, and exploitation was reported.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.6,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.22967,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-04-10",
    "prerequisites": "The attacker must already be running code on the device."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "iOS 16.4.1",
      "iOS 15.7.5",
      "macOS Ventura 13.3.1",
      "macOS Monterey 12.6.5",
      "macOS Big Sur 11.7.6"
    ]
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Update to iOS and iPadOS 16.4.1 or 15.7.5, macOS Ventura 13.3.1, Monterey 12.6.5 or Big Sur 11.7.6 — the browser half of the chain ships with it.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-28206",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-28206",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-28206",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28206",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213720"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213721"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213723"
    }
  ],
  "published_at": "2023-04-10T19:15:07.273Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "apple",
    "ios",
    "macos",
    "kernel",
    "out-of-bounds-write",
    "exploit-chain",
    "kev"
  ]
}
