iPadOS

Security researcher shares PoC for CVE-2023-41992 local privilege escalation bug

iPhone hacked matrix.

When Apple released iOS & iPadOS 16.7 back in 2023, they patched a security vulnerability discovered by Bill Marczak that has since been coined CVE-2023-41992. Apple noted in the online ‘About the security content of iOS 16.7 and iPadOS 16.7’ support document page that this was a kernel vulnerability that may have enabled an attacker to elevate their privileges.

Developers use Ian Beer’s CVE-2025-24203 write-up to bring MacDirtyCow-like tweaks to newer firmware

MDC0 and dirtyZero apps.

In case you didn’t already know, there’s a new kernel exploit out in the wild that renowned Google Project Zero security researcher Ian Beer recently published a writeup about. CVE-2025-24203, which is being referred to by the iPhone & iPad hacking community as dirtyZero or mdc0, is a kernel exploit that allows for certain system customizations akin to what the MacDirtyCow exploit was once capable of on supported firmware.