CVE-2023-42893

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. An app may be able to access protected user data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*

History

10 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/May/10 -
  • () http://seclists.org/fulldisclosure/2024/May/12 -
  • () https://support.apple.com/kb/HT214101 -
  • () https://support.apple.com/kb/HT214106 -

08 Apr 2024, 22:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
Summary
  • (es) Se solucionó un problema de permisos eliminando el código vulnerable y agregando comprobaciones adicionales. Este problema se solucionó en macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 y iPadOS 17.2, iOS 16.7.3 y iPadOS 16.7.3, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Es posible que una aplicación pueda acceder a datos de usuario protegidos.
References () https://support.apple.com/en-us/HT214034 - () https://support.apple.com/en-us/HT214034 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214035 - () https://support.apple.com/en-us/HT214035 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214036 - () https://support.apple.com/en-us/HT214036 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214037 - () https://support.apple.com/en-us/HT214037 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214038 - () https://support.apple.com/en-us/HT214038 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214040 - () https://support.apple.com/en-us/HT214040 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/HT214041 - () https://support.apple.com/en-us/HT214041 - Release Notes, Vendor Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
First Time Apple ipados
Apple watchos
Apple tvos
Apple macos
Apple iphone Os
Apple

28 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-28 16:15

Updated : 2024-06-10 18:15


NVD link : CVE-2023-42893

Mitre link : CVE-2023-42893

CVE.ORG link : CVE-2023-42893


JSON object : View

Products Affected

apple

  • ipados
  • iphone_os
  • macos
  • tvos
  • watchos