Logic Issue in macOS Ventura by Apple
CVE-2023-32364

8.6HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
27 July 2023

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐Ÿ“ฐ News Worthy

Summary

A logic issue in macOS Ventura could allow a sandboxed process to bypass security restrictions, potentially leading to unauthorized access or operations. This vulnerability has been addressed in macOS Ventura version 13.5 with improved restrictions to mitigate the risk of sandbox circumvention.

Affected Version(s)

macOS < 13.5

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Last Week in Security (LWiS) - 2023-10-03

Nighthawk update (@MDSecLabs), Teams external splash bypass, MSI LPEs, and Zip+LNKs (@pfiatde), SCCM takeover (@_Mayyhem), .NET obfuscation (@eversinc33), JonMon (@jsecurity101), and more!

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • ๐Ÿ“ฐ

    First article discovered by Bad Sector Labs Blog

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.